For pre-prod environments in OpenShift clusters like SIT, NFT - developers will be having read-write access across all Kubernetes services like deployments, statefulsets, configmap, daemonset, secrets.
Unplanned changes to secrets causing issues on the applications, so users getting read-write access via IAM user groups on Kubernetes services should be restricted with read-only access for the "secrets"
There should be an additional option to define the access level at resource level for the "kubernetes services" in IAM user group creation steps
| Idea priority | Medium |
| Needed By | Quarter |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.