|
|
|
|
|
by smarterclayton
3409 days ago
|
|
I'm not sure I disagree, but pull vs push with the same ACL rules in place is the same outcome. A secure Kubernetes configuration would also not be able to schedule from a worker. Partition of secrets is important, but anyone able to trigger node compromise still sees secrets and workloads anywhere they can schedule. |
|
Being able to trigger node compromise should have nothing to do with being able to schedule.