Skip to content

Conversation

@mloiseleur
Copy link

What does this PR do?

  1. Disable automount of ServiceAccount token on ServiceAccount level
  2. Enable mount of this ServiceAccount token on Traefik pod level

Motivation

It's recommended (not exhaustive list) by Kubescape, Snyk, CyberArk or OWASP.

Signed-off-by: Michel Loiseleur <michel.loiseleur@traefik.io>
@mloiseleur mloiseleur force-pushed the fix/automountServiceAccountToken branch from e0a97c1 to c1aa59b Compare April 9, 2025 07:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant