Review kube-apiserver static token file authentication

Review static API token lifetime, revocation and storage, and use manageable authentication where needed.

Description

--token-auth-file authenticates to kube-apiserver using static bearer tokens stored in a file. These tokens do not expire automatically, and changes to the token list require an API server restart.

Static token files remain supported, but may be unsuitable where credentials need frequent rotation or prompt revocation. Restrict token storage and distribution and confirm whether this authentication method is needed.

Potential impact

An exposed file or distributed token can be reused with its user and group permissions until revocation takes effect. Poorly planned token changes requiring restarts can also interrupt legitimate clients.

Remediation

  • First prepare replacement authentication and permissions for users and workloads. Consider managed authentication such as OIDC for people and short-lived service account tokens for workloads.
  • When static authentication is no longer needed, remove token-auth-file and apply the change to each API server. Securely remove unnecessary token files and distributed copies.
  • Verify that required operations succeed and old tokens and unapproved requests are rejected. Retained static tokens need minimal permissions, restricted file access and a clear revocation procedure.

Examples

These Kubernetes 1.6 excerpts do not recommend using the old image in current deployments. Actual authentication and authorization require separate configuration.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"
      args:
        - "--token-auth-file=/path/to/any/file"

This enables authentication with static tokens from the specified file. Replacing the example path with a real file does not resolve token-lifetime and storage risks.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"

This removes the static token file option. Configure replacement authentication for legitimate clients first and verify rejection of the old tokens.

References