kube-apiserver service-account-lookup is false

Keep service account token lookups enabled and verify that retired credentials cannot be reused.

Description

--service-account-lookup, which defaults to true, checks stored state during service account token authentication. Disabling this check can prevent deletion of a token or service account from taking effect in authentication, particularly for long-lived Secret-based tokens.

State lookup is separate from token signature validation. Even with lookup enabled, minimize service account permissions and manage token lifetimes.

Potential impact

If an exposed or retired token still authenticates, it can be used to access data or change workloads with the service account’s permissions. The impact also depends on the permissions granted to that account.

Remediation

  • Keep --service-account-lookup=true or its default behavior.
  • Where possible, use short-lived service account tokens through TokenRequest and projected volumes, and grant only required RBAC permissions.
  • Verify that normal workloads continue to work and deleted or revoked tokens are rejected. Remove unnecessary long-lived tokens and distributed copies.

Examples

These excerpts compare historical Kubernetes 1.6 options. Use a supported version and token-management approach for current deployments.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"
      args:
        - "--service-account-lookup=false"

This disables service account token state lookup. It is separate from signature validation and can weaken rejection of retired tokens.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"
      args:
        - "--service-account-lookup=true"

This enables token state lookup. Also manage token lifetimes and service account permissions.

References