-
Notifications
You must be signed in to change notification settings - Fork 150
Closed
Labels
area/securityFor security best practicesFor security best practicesbugSomething isn't workingSomething isn't workingcommunity
Description
Describe the bug
Dataplane PODs (nginx) gets a ServiceAccountToken created and mounted into the POD. That should not be needed. It decreases the security posture and is considered a bad practice.
To Reproduce
Just deploy "getting started" and verify that a ServiceAccount is created for each Gateway and that "automountServiceAccountToken" is set to true for the PODs.
Expected behavior
- No ServiceAccount created
- automountServiceAccountToken set to false
Your environment
- NGF 2.2.1
- kind
- Kubernetes 1.34
Additional context
- Security scanners will detect and report this
Metadata
Metadata
Assignees
Labels
area/securityFor security best practicesFor security best practicesbugSomething isn't workingSomething isn't workingcommunity
Type
Projects
Status
✅ Done