Remove the vlogs one-off oauth-credentials policy #160
Reference in New Issue
Block a user
Delete Branch "benvin/oauth-credentials-any-sa"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The vlogs OIDC client secret moves to its own Kubernetes namespace under service account
default, so it lands onkv/data/kubernetes/namespace/vlogs/default/oauth-credentials. The shared per-namespace rule already matches that path, leaving the vlogs-specific policy with nothing to grant.policies/kv/kubernetes/namespace/logging/default/vlogs-oauth-credentials/read.yaml.The shared oauth-credentials policy is untouched.
No findings.
Scope shared oauth-credentials policy per service accountto Remove the vlogs one-off oauth-credentials policy