Skip to main content

💼 5.1.6 Ensure that Service Account Tokens are only mounted where necessary (Not Scored)

  • ID: /frameworks/cis-gke-v1.0.0/05/01/06

Description​

Service accounts tokens should not be mounted in pods except where the workload running in the pod explicitly needs to communicate with the API server

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS GKE v1.8.0 → 💼 4.1.5 Ensure that Service Account Tokens are only mounted where necessary (Automated)no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance