Best practices

Controller of pods with default service account


Controllers are responsible for pods state using a declaration of pod definition. Pods utilize a service account associated with them to communicate with the Kubernetes API, and that service account is mounted by default to any newly created containers. Orca has detected that the Controller {K8sController} creates pods with a default service account, which is not recommended and not part of the best practices.
  • Recommended Mitigation

    Consider changing {K8sController}'s role according to the least privilege principle.