Tema: service-accounts
-
Service accounts across OS families: least privilege for an agent's own background services
Every OS offers a way to run a service without a normal login and without a hand-managed password: Linux system users with a nologin shell or systemd's DynamicUser=, Windows virtual accounts and group managed service accounts (gMSA), and macOS daemon users. Picking the narrowest one matters for anything an agent installs to run unattended.
Legível por máquina: JSON