Description
--service-account-lookup, which defaults to true, checks stored state during service account token authentication. Disabling this check can prevent deletion of a token or service account from taking effect in authentication, particularly for long-lived Secret-based tokens.
State lookup is separate from token signature validation. Even with lookup enabled, minimize service account permissions and manage token lifetimes.
Potential impact
If an exposed or retired token still authenticates, it can be used to access data or change workloads with the service account’s permissions. The impact also depends on the permissions granted to that account.
Remediation
- Keep
--service-account-lookup=trueor its default behavior. - Where possible, use short-lived service account tokens through TokenRequest and projected volumes, and grant only required RBAC permissions.
- Verify that normal workloads continue to work and deleted or revoked tokens are rejected. Remove unnecessary long-lived tokens and distributed copies.
Examples
These excerpts compare historical Kubernetes 1.6 options. Use a supported version and token-management approach for current deployments.
Before
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command:
- "kube-apiserver"
args:
- "--service-account-lookup=false"
This disables service account token state lookup. It is separate from signature validation and can weaken rejection of retired tokens.
After
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command:
- "kube-apiserver"
args:
- "--service-account-lookup=true"
This enables token state lookup. Also manage token lifetimes and service account permissions.