Skip to content

Clusterrole does not have 'get' permissions on pods #224

@ajcann

Description

@ajcann

Going over cluster api audit logs, I see aws-node-termination-handler attempts to use the 'get' verb on pod resources but these requests are rejected. I see that the helm chart's clusterrole specifies list but not get get.

Will this harm functionality in anyway? Should we amend the clusterrole to have get permissions or is this get request unintentional?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type: QuestionAll types of questions to/from customers

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions