Description
--disable-admission-plugins=ServiceAccount disables the ServiceAccount admission plugin. The plugin assigns a default service account, checks that the referenced account exists, and applies token volumes and image pull credentials according to the configuration.
Disabling it can change expected service-account behavior. Keep it enabled in operational clusters.
Potential impact
- Default associations between Pods and service accounts can be lost.
- Service-account validation and defaults may no longer be applied.
- Token and access-control configuration can become inconsistent.
Remediation
- Remove
ServiceAccountfrom--disable-admission-plugins. - If needed, explicitly include
ServiceAccountin--enable-admission-plugins. - Check how the change affects running workloads.
Examples
These are container command and argument excerpts for a supported kube-apiserver. Configure the image and other required control-plane settings separately.
Before
yaml
command: ["kube-apiserver"]
args: ["--disable-admission-plugins=ServiceAccount"]
After
yaml
command: ["kube-apiserver"]
args: ["--enable-admission-plugins=ServiceAccount"]
Explanation:
- Before: Disabling the plugin removes its service-account checks and defaults.
- After: Enabling it retains those checks and normal service-account behavior.