kyma-project / infrastructure-manager

Apache License 2.0
0 stars 10 forks source link

[Threat Modeling] Improve secure configuration of KIM #357

Open TorstenD-SAP opened 3 months ago

TorstenD-SAP commented 3 months ago

Description

Kubescape still reports some miss-configurations. It has to be checked, if the secure configuration of KIM can be improved. Especially the following settings have to be checked:

See also https://help.sap.com/docs/BTP/65de2977205c403bbc107264b8eccf4b/f8cb6e55496b4bd1be68d6dfa4d15487.html?locale=en-US

Reasons

Reduce the attack surface

Attachments

Disper commented 5 days ago

powerful permissions of the ServiceAccount used (Kubescape Control C-0267)

Related issue https://github.com/kyma-project/infrastructure-manager/issues/56

Disper commented 4 days ago

PRs: (internal) - charts#2295

tobiscr commented 2 days ago

PRs: (internal) - charts#2295

and PR (internal) - mgt-plane-charts#2288