Ensure that the Tiller Service (Helm v2) is not deployed for Kubernetes service

MEDIUM

Description

Provided Tiller Service (Helm v2) has been deployed in your Kubernetes cluster, there is high probability that the users can get broad range of permissions.

Remediation

Restricting access to Tiller from within the cluster limits the abilities of a compromised pod or anonymous user in the cluster. Therefore, it is recommended to upgrade Helm v3, which no longer requires or includes the Tiller service.

Policy Details

Rule Reference ID: AC_K8S_0110
Remediation Available: No
Resource Category: Management
Resource Type: Service

Frameworks