Description
Workloads using a namespace’s default ServiceAccount share the same API identity. The default account is not inherently an administrator, but additional permissions granted to it apply to workloads using that identity.
Sharing the account does not mean every pod receives the same token value. Review actual RBAC permissions and whether each pod needs a token automatically mounted.
Potential impact
- A token exposed through one workload can be used to exercise the shared account’s permissions.
- Separating and auditing permissions by workload can become harder.
Remediation
- Use a dedicated ServiceAccount with minimal RBAC permissions for workloads that need API access. Set
automount_service_account_token = falseon pods that do not need a token. - Remove unnecessary permissions and token automounting from the default ServiceAccount, and check for pod-level overrides. Verify the effective settings on newly created pods.
Examples
Import the existing default ServiceAccount before managing it with Terraform. The examples compare account-level automounting only; they do not move workloads to a dedicated account or revoke permissions. Pod-level settings take precedence.
Before
hcl
resource "kubernetes_service_account" "example" {
metadata {
name = "default"
}
automount_service_account_token = true
}
After
hcl
resource "kubernetes_service_account" "example" {
metadata {
name = "default"
}
automount_service_account_token = false
}
Explanation:
- Before: Token automounting is allowed at the default account level. Check actual pod settings and API access needs.
- After: Account-level automounting is disabled. This does not revoke tokens in existing pods or remove RBAC permissions.