KubeLinter

KubeLinter

Community Analyzer

Unrestricted access to Secrets KUBELIN-W1002

Anti-pattern
Major

Indicates when a subject (Group/User/ServiceAccount) has access to Secrets. CIS Benchmark 5.1.2: Access to secrets should be restricted to the smallest possible group of users to reduce the risk of privilege escalation.

Remediation

Where possible, remove get, list and watch access to secret objects in the cluster.