serviceaccount-token-automount
A ServiceAccount that automounts by default puts its API token into every pod that references it, so any one compromised container yields a credential usable against the API server.
has(object.automountServiceAccountToken) && object.automountServiceAccountToken == false
automountServiceAccountToken must be set to false by default on ServiceAccounts.
Set automountServiceAccountToken to false on the ServiceAccount and opt individual pods back in only where API access is required. Field: automountServiceAccountToken.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: serviceaccount-token-automount
annotations:
kubeapt.io/uuid: "8076b964-2115-4b03-8785-3d5bc43325c4"
security.kubeapt.io/displayName: "Automounts Its Token Into Every Pod"
security.kubeapt.io/description: "A ServiceAccount that automounts by default puts its API token into every pod that references it, so any one compromised container yields a credential usable against the API server."
security.kubeapt.io/resource: "ServiceAccounts"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Set automountServiceAccountToken to false on the ServiceAccount and opt individual pods back in only where API access is required. Field: automountServiceAccountToken."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- serviceaccounts
validations:
- expression: |
has(object.automountServiceAccountToken) && object.automountServiceAccountToken == false
message: |
automountServiceAccountToken must be set to false by default on ServiceAccounts.Save it as serviceaccount-token-automount.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./serviceaccount-token-automount.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name serviceaccount-token-automount -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name serviceaccount-token-automount -A