-
Notifications
You must be signed in to change notification settings - Fork 1.1k
fix(security): Service account permissions should be restricted. Add sample file samples/juicefs/read_job.yaml. #5242
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…sample file samples/juicefs/read_job.yaml. Signed-off-by: JiGuoDing <485204300@qq.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #5242 +/- ##
==========================================
- Coverage 55.51% 55.50% -0.01%
==========================================
Files 443 443
Lines 30382 30438 +56
==========================================
+ Hits 16867 16896 +29
- Misses 11962 11978 +16
- Partials 1553 1564 +11 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
/lgtm |
Signed-off-by: JiGuoDing <485204300@qq.com>
Signed-off-by: JiGuoDing <485204300@qq.com>
Signed-off-by: JiGuoDing <485204300@qq.com>
|
cheyang
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: cheyang The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
…sample file samples/juicefs/read_job.yaml. (fluid-cloudnative#5242) * fix(security): Service account permissions should be restricted. Add sample file samples/juicefs/read_job.yaml. Signed-off-by: JiGuoDing <485204300@qq.com> * fix: add memory limit to comply with security policy Signed-off-by: JiGuoDing <485204300@qq.com> * fix: add storage limit to comply with security policy Signed-off-by: JiGuoDing <485204300@qq.com> * fix: alter storage limit to comply with security policy Signed-off-by: JiGuoDing <485204300@qq.com> --------- Signed-off-by: JiGuoDing <485204300@qq.com>



Ⅰ. Describe what this PR does
This PR addresses the security finding “Service account permissions should be restricted” by introducing a new hardened sample Job manifest
samples/juicefs/read_job.yaml.The sample demonstrates how to securely configure a Kubernetes Job that reads from a PVC without requiring Kubernetes API access, by explicitly setting:
Ⅱ. Does this pull request fix one issue?
fixes #XXXX
Ⅲ. List the added test cases (unit test/integration test) if any, please explain if no tests are needed.
No automated tests are required.
Ⅳ. Describe how to verify it
Ⅴ. Special notes for reviews