turbot/gcp_compliance

Query: kubernetes_cluster_service_account_default

Usage

powerpipe query gcp_compliance.query.kubernetes_cluster_service_account_default

Steampipe Tables

SQL

select
self_link resource,
case
when node_config ->> 'ServiceAccount' = 'default' then 'alarm'
else 'ok'
end as status,
case
when node_config ->> 'ServiceAccount' = 'default' then title || ' default service account is used for project access.'
else title || ' default service account is not used for project access.'
end as reason
, location as location, project as project
from
gcp_kubernetes_cluster;

Controls

The query is being used by the following controls: