← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Uses the Default ServiceAccount

pod-serviceaccount-name

severityLow resourcePods productKubernetes bundles1

Running under the namespace default ServiceAccount makes every workload share one identity, so any permission granted to it reaches all of them and API audit records cannot be traced back to a single pod.

Rejects unless

has(object.spec.serviceAccountName) && size(object.spec.serviceAccountName) > 0 && object.spec.serviceAccountName != "default"

spec.serviceAccountName must be set to a non-default service account.

Remediation

Create a dedicated ServiceAccount holding only the permissions this workload needs and set spec.serviceAccountName to it. Field: spec.serviceAccountName.

Applies to

  • pods · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: pod-serviceaccount-name
  annotations:
    kubeapt.io/uuid: "1e4e5442-122f-4dd9-86ce-a6104971b13b"
    security.kubeapt.io/displayName: "Uses the Default ServiceAccount"
    security.kubeapt.io/description: "Running under the namespace default ServiceAccount makes every workload share one identity, so any permission granted to it reaches all of them and API audit records cannot be traced back to a single pod."
    security.kubeapt.io/resource: "Pods"
    security.kubeapt.io/severity: "Low"
    security.kubeapt.io/remediation: "Create a dedicated ServiceAccount holding only the permissions this workload needs and set spec.serviceAccountName to it. Field: spec.serviceAccountName."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods
  validations:
  - expression: |
      has(object.spec.serviceAccountName) && size(object.spec.serviceAccountName) > 0 && object.spec.serviceAccountName != "default"
    message: |
      spec.serviceAccountName must be set to a non-default service account.

Save it as pod-serviceaccount-name.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./pod-serviceaccount-name.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name pod-serviceaccount-name -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name pod-serviceaccount-name -A