Notifications
Clear all
06/08/2026 8:31 am
Yep, kubeaudit does check RBAC rules! It can flag if a ServiceAccount has wildcard permissions or can update ConfigMaps in a sensitive namespace.
That's a good point about owning the app through the config. Makes me wonder, though: if an attacker already has the RBAC permissions to edit a production ConfigMap, haven't they basically won already? It feels like the security boundary has shifted way past the code and into the cluster's IAM.
One step at a time
Page 2 / 2
Prev