Description
--service-account-private-key-file enables legacy Secret-based service account token generation in kube-controller-manager and specifies the private signing key. Current TokenRequest-based issuance uses the kube-apiserver signing configuration, so omitting this controller option does not stop all token issuance.
Service account tokens are commonly used for cluster authentication. Configure keys for the token issuance method actually in use.
Potential impact
- Missing or incorrect keys can disrupt token generation and authentication where legacy tokens are required.
- Exposure of the signing private key can allow token forgery.
Remediation
- Prefer time-limited TokenRequest-based tokens. Configure
--service-account-private-key-filein kube-controller-manager only when legacy Secret-based tokens are required. - Protect the private key’s file permissions and storage location.
- Ensure kube-apiserver has the corresponding verification key. Do not enable unnecessary long-lived tokens just to populate this option.
Examples
These are historical Kubernetes 1.6 excerpts for legacy tokens. Use a supported version in production and configure key-file mounts and the remaining control-plane settings separately.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
command: ["kube-controller-manager"]
args: []
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
command: ["kube-controller-manager"]
args: ["--service-account-private-key-file=/path/to/key/file.pem"]
Explanation:
- Before: No private key for signing legacy tokens is specified. Check the token issuance method and requirements in use.
- After: A signing key for legacy tokens is specified. A valid private key and its corresponding verification key are required.