ServiceAccount admission plugin disabled

Disabling the ServiceAccount admission plugin removes service-account defaults and checks for Pods.

Description

--disable-admission-plugins=ServiceAccount disables the ServiceAccount admission plugin. The plugin assigns a default service account, checks that the referenced account exists, and applies token volumes and image pull credentials according to the configuration.

Disabling it can change expected service-account behavior. Keep it enabled in operational clusters.

Potential impact

  • Default associations between Pods and service accounts can be lost.
  • Service-account validation and defaults may no longer be applied.
  • Token and access-control configuration can become inconsistent.

Remediation

  • Remove ServiceAccount from --disable-admission-plugins.
  • If needed, explicitly include ServiceAccount in --enable-admission-plugins.
  • Check how the change affects running workloads.

Examples

These are container command and argument excerpts for a supported kube-apiserver. Configure the image and other required control-plane settings separately.

Before

yaml
command: ["kube-apiserver"]
args: ["--disable-admission-plugins=ServiceAccount"]

After

yaml
command: ["kube-apiserver"]
args: ["--enable-admission-plugins=ServiceAccount"]

Explanation:

  • Before: Disabling the plugin removes its service-account checks and defaults.
  • After: Enabling it retains those checks and normal service-account behavior.

References