Individual controller service account credentials disabled

Without individual service account credentials, kube-controller-manager can give controllers broader permissions than they need.

Description

--use-service-account-credentials=true makes each controller use separate service account credentials. When disabled, controllers may use shared credentials with broader permissions than each needs. This does not isolate controllers running in the same process.

Using only the permissions needed by each controller helps protect the control plane. Enable this option in operational clusters.

Potential impact

  • Controllers can use an unnecessarily broad shared permission scope.
  • An incorrect API request by a controller can execute with greater permissions.
  • Applying least privilege to individual controllers becomes harder.

Remediation

  • Set --use-service-account-credentials=true on kube-controller-manager.
  • Review the service accounts and permissions for each controller.
  • Include this option in controller-manager security checks.

Examples

These examples compare options from Kubernetes 1.6. Use a supported version in production and configure the other required control-plane settings separately.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
      command: ["kube-controller-manager", "--use-service-account-credentials=false"]
      args: []

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
      command: ["kube-controller-manager"]
      args: ["--use-service-account-credentials=true"]

Explanation:

  • Before: Disabling separate service account credentials weakens permission separation between controllers.
  • After: Individual service account credentials improve controller-specific permission separation.

References