Delete secrets Kubernetes ClusterRole warns about viewing secrets #6713
Replies: 5 comments
-
cc @chen-keinan |
Beta Was this translation helpful? Give feedback.
-
@evankanderson can you please add your expected results |
Beta Was this translation helpful? Give feedback.
-
I would expect no warnings -- users do not have access to read secrets. |
Beta Was this translation helpful? Give feedback.
-
Note that the only permission granted is I don't want to disable this warning altogether, but I'm having trouble how having only
Since no |
Beta Was this translation helpful? Give feedback.
-
(There might be an argument that could be constructed around granting only |
Beta Was this translation helpful? Give feedback.
-
IDs
ksv041
Description
Using trivy to scan a manifest with a ClusterRole that grants delete only on secrets leads to the following critical warning:
Reproduction Steps
trivy fs --scanners misconfig
on the file or a directory containing it, and get the warning aboveTarget
Filesystem
Scanner
Misconfiguration
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions