PageSourceSearch

https://flanksource.com/assets/js/a37c458b.681cc170.js

js flanksource.com collected 2026-09-25 15:26:55 UTC 2,873 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkmission_control=globalThis.webpackChunkmission_control||[]).push([[4006],{58102(e,n,r){r.r(n),r.d(n,{assets:()=>a,contentTitle:()=>i,default:()=>l,frontMatter:()=>o,metadata:()=>t,toc:()=>u});const t=JSON.parse('{"id":"hardening","title":"Hardening","description":"Service Account RBAC","source":"@site/docs/hardening.md","sourceDirName":".","slug":"/security/hardening","permalink":"/docs/security/hardening","draft":false,"unlisted":false,"editUrl":"https://github.com/flanksource/docs/tree/main/docs/hardening.md","tags":[],"version":"current","sidebarPosition":100,"frontMatter":{"title":"Hardening","sidebar_position":100,"slug":"security/hardening"},"sidebar":"overview","previous":{"title":"Security","permalink":"/docs/security"}}');var s=r(74848),c=r(28453);const o={title:"Hardening",sidebar_position:100,slug:"security/hardening"},i=void 0,a={},u=[{value:"Service Account RBAC",id:"service-account-rbac",level:2}];function d(e){const n={code:"code",h2:"h2",p:"p",pre:"pre",...(0,c.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.h2,{id:"service-account-rbac",children:"Service Account RBAC"}),"\n",(0,s.jsx)(n.p,{children:"Canary Checker, by default, uses a highly permissive service account.\nYou can configure the permissions on that service account via the helm values."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",metastring:'title="values.yaml"',children:"....\nrbac:\n  # Whether to create cluster-wide or namespaced roles\n  cluster_role: false\n\n  # for secret management with valueFrom\n  tokenRequest: true\n  secrets: true\n  configmaps: true\n\n  # for use with kubernetes resource lookups\n  readAll: true\n\n  # for pod and junit canaries\n  podsCreateAndDelete: true\n\n  # for pod canary\n  ingressCreateAndDelete: true\n\n  # for kubernetes resource check & namespace check\n  namespaceCreateAndDelete: true\n"})}),"\n",(0,s.jsx)(n.p,{children:"The first thing to decide on is whether to grant cluster role access or namespace access\nto the service account."}),"\n",(0,s.jsxs)(n.p,{children:["If certain checks do not need to be performed, the corresponding permissions required for them can be disabled.\nExample: the ",(0,s.jsx)(n.code,{children:"readAll"})," permission is essential to run the Kubernetes lookup check."]})]})}function l(e={}){const{wrapper:n}={...(0,c.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},28453(e,n,r){r.d(n,{R:()=>o,x:()=>i});var t=r(96540);const s={},c=t.createContext(s);function o(e){const n=t.useContext(c);return t.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function i(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:o(e.components),t.createElement(c.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.