Description
When a Role or ClusterRole grants get, watch, list or broader access to secrets and is bound to a ServiceAccount, Pods using that account can read Secret values. Secrets can contain tokens, passwords and keys.
Grant these permissions only to workloads that need them. Do not give ordinary service accounts Secret read access by default.
Potential impact
- Pods can read sensitive passwords, tokens and keys.
- A compromised workload can use these credentials to access other systems.
- More identities with Secret access can make incident investigation harder.
Remediation
- Remove unnecessary Secret read permissions from bound Roles and ClusterRoles.
- Use dedicated ServiceAccounts for workloads that need Secret access.
- Treat
resources: ["secrets"]and read verbs as sensitive permissions during RBAC reviews.
Examples
Create the example ServiceAccount testsa separately in the assembly-prod namespace. Secret update permission can also allow credential tampering and is not a safe substitute for read access.
Before
yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: assembly-prod
name: testRoleVulnerable
rules:
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get", "watch", "list"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: assembly-prod
name: testRoleBinding
subjects:
- kind: ServiceAccount
name: testsa
namespace: assembly-prod
roleRef:
kind: Role
name: testRoleVulnerable
apiGroup: rbac.authorization.k8s.io
After
yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: assembly-prod
name: testRoleWithBindingSafe
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: assembly-prod
name: bindingtestRoleWithBindingSafe
subjects:
- kind: ServiceAccount
name: testsa
namespace: assembly-prod
roleRef:
kind: Role
name: testRoleWithBindingSafe
apiGroup: rbac.authorization.k8s.io
Explanation:
- Before: The binding grants the ServiceAccount access to Secret values.
- After: This role grants only Pod read access instead. Check other bindings for remaining Secret permissions.