Skip to content

Latest commit

 

History

History
19 lines (13 loc) · 804 Bytes

default-service-account.md

File metadata and controls

19 lines (13 loc) · 804 Bytes

CloudSploit

GOOGLE / Kubernetes / Default Service Account

Quick Info

Plugin Title Default Service Account
Cloud GOOGLE
Category Kubernetes
Description Ensures all Kubernetes cluster nodes are not using the default service account.
More Info Kubernetes cluster nodes should use customized service accounts that have minimal privileges to run. This reduces the attack surface in the case of a malicious attack on the cluster.
GOOGLE Link https://cloud.google.com/container-optimized-os/
Recommended Action Ensure that no Kubernetes cluster nodes are using the default service account

Detailed Remediation Steps