Priority: HIGH
Description
ServiceAccount is referenced in 6/8 deployment manifests but not defined as a ConfigHub unit. This violates PCI-DSS 8.2 (Unique IDs) requirements.
Impact
- Pods cannot start without the ServiceAccount
- No RBAC policies are defined, allowing excessive permissions
- Compliance violation for regulated environments
Required Actions
- Create ServiceAccount manifests for each namespace
- Define Role and RoleBinding with least privilege
- Add NetworkPolicy for pod-to-pod communication
- Document RBAC model
Acceptance Criteria
References
- Original finding in SECURITY-REVIEW.md (now archived)
- PCI-DSS 8.2 compliance requirement
Priority: HIGH
Description
ServiceAccount is referenced in 6/8 deployment manifests but not defined as a ConfigHub unit. This violates PCI-DSS 8.2 (Unique IDs) requirements.
Impact
Required Actions
Acceptance Criteria
References