Review ServiceAccount token automounting

Disable automatic token mounts for pods that do not need Kubernetes API tokens.

Description

An automatically mounted ServiceAccount token makes that account’s Kubernetes API credential available to the pod. It is unnecessary for workloads that do not call the API. Check the actual Pod and ServiceAccount settings together; the Pod setting takes precedence.

Unnecessary tokens can be exposed through application vulnerabilities or inappropriate debugging tools. Explicitly allow them only where needed.

Potential impact

  • Pods that do not need API access can still receive a token.
  • A compromised container can use the account’s granted permissions for further discovery or misuse.

Remediation

  • Set automount_service_account_token = false on pods and workload templates that do not need a Kubernetes API token.
  • Use purpose-specific ServiceAccounts with minimum permissions where tokens are needed, and provide tokens with the required audience and lifetime. Check other credential paths, including explicitly configured token volumes.

Examples

The DaemonSet examples compare automatic mounting only. Prepare the namespace separately and choose a maintained image for deployment. This option does not remove explicitly configured token volumes.

Before

hcl
resource "kubernetes_daemonset" "example" {
  metadata {
    name      = "terraform-example"
    namespace = "something"
  }

  spec {
    selector {
      match_labels = {
        test = "MyExampleApp"
      }
    }

    template {
      metadata {
        labels = {
          test = "MyExampleApp"
        }
      }

      spec {
        automount_service_account_token = true

        container {
          image = "nginx:1.7.8"
          name  = "example"
        }
      }
    }
  }
}

After

hcl
resource "kubernetes_daemonset" "example" {
  metadata {
    name      = "terraform-example"
    namespace = "something"
  }

  spec {
    selector {
      match_labels = {
        test = "MyExampleApp"
      }
    }

    template {
      metadata {
        labels = {
          test = "MyExampleApp"
        }
      }

      spec {
        automount_service_account_token = false

        container {
          image = "nginx:1.7.8"
          name  = "example"
        }
      }
    }
  }
}

Explanation:

  • Before: Automatic token mounting is allowed. This unnecessarily exposes credentials when the pod does not need an API token.
  • After: Automatic mounting is disabled. Review functions that need tokens separately.

References