← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Automounts Its Token Into Every Pod

serviceaccount-token-automount

severityModerate resourceServiceAccounts productKubernetes bundles1

A ServiceAccount that automounts by default puts its API token into every pod that references it, so any one compromised container yields a credential usable against the API server.

Rejects unless

has(object.automountServiceAccountToken) && object.automountServiceAccountToken == false

automountServiceAccountToken must be set to false by default on ServiceAccounts.

Remediation

Set automountServiceAccountToken to false on the ServiceAccount and opt individual pods back in only where API access is required. Field: automountServiceAccountToken.

Applies to

  • serviceaccounts · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: serviceaccount-token-automount
  annotations:
    kubeapt.io/uuid: "8076b964-2115-4b03-8785-3d5bc43325c4"
    security.kubeapt.io/displayName: "Automounts Its Token Into Every Pod"
    security.kubeapt.io/description: "A ServiceAccount that automounts by default puts its API token into every pod that references it, so any one compromised container yields a credential usable against the API server."
    security.kubeapt.io/resource: "ServiceAccounts"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Set automountServiceAccountToken to false on the ServiceAccount and opt individual pods back in only where API access is required. Field: automountServiceAccountToken."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - serviceaccounts
  validations:
  - expression: |
      has(object.automountServiceAccountToken) && object.automountServiceAccountToken == false
    message: |
      automountServiceAccountToken must be set to false by default on ServiceAccounts.

Save it as serviceaccount-token-automount.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./serviceaccount-token-automount.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name serviceaccount-token-automount -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name serviceaccount-token-automount -A