Skip to main content

More Info:

The pods/create permission lets a principal effectively run code as any service account in the namespace. Limit it to controllers and CI accounts and audit any human grant.

Risk Level

High

Address

Compliance, Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.