kubernetes-sigs/cluster-api
Security Self Assessment: [STRIDE-SPOOF-4][STRIDE-SPOOF-5] Machine attestation for secure kubelet registration
オープン
#3,762 opened on 2020/10/07
area/securityhelp wantedkind/featurepriority/important-longtermsig/securitytriage/accepted
Repository metrics
- Stars
- (4,267 個のスター)
- PR merge metrics
- (PR metrics pending)
説明
User Story
As a security operator, I want to ensure developers who have access to create MachineDeployments are not able to gain access to data for workloads on a cluster they are not supposed to.
Detailed Description
kubeadm bootstrap tokens allow registration as arbitrary node names. GCP, EKS and Kops provide mechanisms to attest to the identity of a node such that they do not inadvertently get access to secrets and volumes not intended for that node. Provide a mechanism to resolve.
Anything else you would like to add:
[Miscellaneous information that will assist in solving the issue.]
/kind feature