問題文
A namespace grants a developer permission to create Pods. Why does that permission need to be reviewed as carefully as a permission to read Secrets in the same namespace?
選択肢
- Pod creation implicitly grants the escalate verb on Roles in the namespace, so the developer can widen the grant without further review.
- Creating a Pod requires the API server to write a new object into etcd, and each of those writes is replicated to every member of the etcd cluster.
- A Pod can mount any Secret in its namespace, so being able to create Pods indirectly gives access to the contents of those Secrets.
- Pod creation bypasses the Pod Security Admission controller, so a Pod that violates the namespace profile still starts on a node in the cluster.