Skip to content

Helm chart: RBAC Wildcard In Rule #6434

@blsho

Description

@blsho

KICS scan reports high vulnerability (risk score 8.4) RBAC Wildcard In Rule when it scans templated external-dns chart to kubernetes manifest files.

Reference: https://docs.kics.io/latest/queries/kubernetes-queries/6b896afb-ca07-467a-b256-1a0077a1c08e/

Location: https://github.com/kubernetes-sigs/external-dns/blob/v0.21.0/charts/external-dns/templates/clusterrole.yaml#L61

What would you like to be added:

Explicitly name verbs which are needed for dnsendpoints/status resource.

Why is this needed:

security, to pass KICS scans.

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/featureCategorizes issue or PR as related to a new feature.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions