ServiceAccount access to Secrets

Secret read permissions allow a ServiceAccount and its workloads to access sensitive credentials.

Description

When a Role or ClusterRole grants get, watch, list or broader access to secrets and is bound to a ServiceAccount, Pods using that account can read Secret values. Secrets can contain tokens, passwords and keys.

Grant these permissions only to workloads that need them. Do not give ordinary service accounts Secret read access by default.

Potential impact

  • Pods can read sensitive passwords, tokens and keys.
  • A compromised workload can use these credentials to access other systems.
  • More identities with Secret access can make incident investigation harder.

Remediation

  • Remove unnecessary Secret read permissions from bound Roles and ClusterRoles.
  • Use dedicated ServiceAccounts for workloads that need Secret access.
  • Treat resources: ["secrets"] and read verbs as sensitive permissions during RBAC reviews.

Examples

Create the example ServiceAccount testsa separately in the assembly-prod namespace. Secret update permission can also allow credential tampering and is not a safe substitute for read access.

Before

yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: testRoleVulnerable
rules:
  - apiGroups: [""]
    resources: ["secrets"]
    verbs: ["get", "watch", "list"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: testRoleBinding
subjects:
  - kind: ServiceAccount
    name: testsa
    namespace: assembly-prod
roleRef:
  kind: Role
  name: testRoleVulnerable
  apiGroup: rbac.authorization.k8s.io

After

yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: testRoleWithBindingSafe
rules:
  - apiGroups: [""]
    resources: ["pods"]
    verbs: ["get", "list"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: bindingtestRoleWithBindingSafe
subjects:
  - kind: ServiceAccount
    name: testsa
    namespace: assembly-prod
roleRef:
  kind: Role
  name: testRoleWithBindingSafe
  apiGroup: rbac.authorization.k8s.io

Explanation:

  • Before: The binding grants the ServiceAccount access to Secret values.
  • After: This role grants only Pod read access instead. Check other bindings for remaining Secret permissions.

References