kubernetes-sigs / gcp-compute-persistent-disk-csi-driver

The Google Compute Engine Persistent Disk (GCE PD) Container Storage Interface (CSI) Storage Plugin.
Apache License 2.0
163 stars 143 forks source link

Read Security Audit & Use Findings #377

Open davidz627 opened 5 years ago

davidz627 commented 5 years ago

Read: https://github.com/kubernetes/community/blob/master/wg-security-audit/findings/Kubernetes%20Final%20Report.pdf

From a quick skim some things already stand out as directly applicable to this driver. See 8) Pervasive world-accessible file permissions 34) Hardcoded use of insecure gRPS transport (TBC) 23) Hard-coded credential paths

fejta-bot commented 4 years ago

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale. Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Send feedback to sig-testing, kubernetes/test-infra and/or fejta. /lifecycle stale

davidz627 commented 4 years ago

/remove-lifecycle stale /lifecycle frozen