[MEDIUM] Disable automountServiceAccountToken where not needed #23

Closed
opened 2026-07-28 14:31:50 +00:00 by sorb · 1 comment
Owner

Audit all Deployments/StatefulSets in matrix and authentik namespaces, add automountServiceAccountToken: false wherever the pod doesn't actually need Kubernetes API access (Synapse, ElementWeb, MAS, Postgres, Authentik, etc). Test for no breakage.

Audit all Deployments/StatefulSets in `matrix` and `authentik` namespaces, add `automountServiceAccountToken: false` wherever the pod doesn't actually need Kubernetes API access (Synapse, ElementWeb, MAS, Postgres, Authentik, etc). Test for no breakage.
sorb added the priority:mediumarea:security labels 2026-07-28 14:31:50 +00:00
Author
Owner

Migriert nach git.lab: axion1337.chat/axion1337.chat-gitops#23 (nur im Lab bzw. via VPN erreichbar — das Lab ist seit 2026-08-01 die Quelle der Wahrheit, siehe gitops#48). Weiterarbeit dort; dieses Gitea-Issue bleibt als Verweis stehen.

**Migriert nach git.lab**: [axion1337.chat/axion1337.chat-gitops#23](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/23) (nur im Lab bzw. via VPN erreichbar — das Lab ist seit 2026-08-01 die Quelle der Wahrheit, siehe gitops#48). Weiterarbeit dort; dieses Gitea-Issue bleibt als Verweis stehen.
sorb closed this issue 2026-08-01 14:26:04 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sorb/axion1337.chat-gitops#23