Skip to content

Document API convention for PII #21560

Closed
Closed
@bgrant0607

Description

I'd like to come up with a simple rule about PII in the API, such as:

  • The following things are considered PII
    • User object names
    • User labels and annotations
    • Image names
    • Commands, args, env
    • ConfigMap entries
    • Secret entries
  • PII shouldn't be recorded in non-namespaced resources (e.g., nodes) other than namespaces themselves

This has come up twice recently.

cc @erictune @smarterclayton @liggitt @deads2k @davidopp

Metadata

Assignees

No one assigned

    Labels

    area/apiIndicates an issue on api area.kind/documentationCategorizes issue or PR as related to documentation.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.priority/backlogHigher priority than priority/awaiting-more-evidence.sig/architectureCategorizes an issue or PR as relevant to SIG Architecture.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions