Review service account token verification keys

Review the keys and trust configuration kube-apiserver uses to verify service account tokens.

Description

--service-account-key-file specifies a PEM key file for verifying service account token signatures. When it is omitted, kube-apiserver uses the key from --tls-private-key-file; omission alone does not disable token verification.

Service account tokens are commonly used for cluster access. The verification keys must match the token signing configuration.

Potential impact

  • Mismatched signing and verification keys can prevent valid tokens from authenticating.
  • Trusting unnecessary keys can admit tokens from unintended issuers.

Remediation

  • When using local signing keys, configure their corresponding verification keys with --service-account-key-file. This option is also required when using --service-account-signing-key-file.
  • Document key management and distribute signing and verification keys consistently.
  • Check file paths and permissions. For versions and configurations using an external signer, follow that verification setup and do not combine mutually exclusive local key options.

Examples

These are historical Kubernetes 1.6 configuration excerpts. Use a supported version in production and configure the required key-file mounts and other control-plane settings separately.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args: []

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args: ["--service-account-key-file=/path/to/file.pem"]

Explanation:

  • Before: No verification key file is specified. Review the actual fallback key or external signing configuration.
  • After: A verification key file is explicit. The path must exist and contain a key corresponding to the actual signing key.

References