Description
Unless automountServiceAccountToken is disabled, a Pod may receive a service account token automatically. If the application does not call the Kubernetes API, this credential is unnecessary.
When the Pod has no setting, the ServiceAccount setting applies; if both specify a value, the Pod setting takes precedence. Unnecessary tokens may be exposed through application vulnerabilities or debugging tools. Explicitly allow them only where needed.
Potential impact
- Pods that do not need Kubernetes API access may hold access tokens.
- A compromised container can expose a token for use against other resources.
- Workload requirements for API access can become unclear.
Remediation
- Set
automountServiceAccountToken: falsefor Pods that do not need the Kubernetes API. - Decide explicitly whether each workload needs a token rather than relying on defaults.
- Use dedicated ServiceAccounts with limited permissions for workloads that require tokens.
Examples
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: security.context.demo
spec:
automountServiceAccountToken: true
containers:
- name: sec-ctx-demo
image: busybox
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
automountServiceAccountToken: false
containers:
- name: sec-ctx-demo
image: busybox
Explanation:
- Before: A token can be mounted even if the Pod does not need it.
- After: Disabling automatic mounting reduces token exposure. It does not revoke the account’s RBAC permissions or remove credentials supplied separately.