Automatic service account token mounting not disabled

Automatically mounting service account tokens in Pods that do not need them unnecessarily exposes Kubernetes API credentials.

Description

Unless automountServiceAccountToken is disabled, a Pod may receive a service account token automatically. If the application does not call the Kubernetes API, this credential is unnecessary.

When the Pod has no setting, the ServiceAccount setting applies; if both specify a value, the Pod setting takes precedence. Unnecessary tokens may be exposed through application vulnerabilities or debugging tools. Explicitly allow them only where needed.

Potential impact

  • Pods that do not need Kubernetes API access may hold access tokens.
  • A compromised container can expose a token for use against other resources.
  • Workload requirements for API access can become unclear.

Remediation

  • Set automountServiceAccountToken: false for Pods that do not need the Kubernetes API.
  • Decide explicitly whether each workload needs a token rather than relying on defaults.
  • Use dedicated ServiceAccounts with limited permissions for workloads that require tokens.

Examples

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security.context.demo
spec:
  automountServiceAccountToken: true
  containers:
    - name: sec-ctx-demo
      image: busybox

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  automountServiceAccountToken: false
  containers:
    - name: sec-ctx-demo
      image: busybox

Explanation:

  • Before: A token can be mounted even if the Pod does not need it.
  • After: Disabling automatic mounting reduces token exposure. It does not revoke the account’s RBAC permissions or remove credentials supplied separately.

References