ServiceAccount의 Secret 접근 허용

ServiceAccount에 Secret 읽기 권한이 연결되면 파드가 민감한 자격 증명에 접근할 수 있습니다.

설명

Role 또는 ClusterRole에 secrets에 대한 get, watch, list 또는 광범위한 권한이 있고, 그 역할이 ServiceAccount에 바인딩되면 해당 계정을 사용하는 파드는 Secret 값을 읽을 수 있습니다. Secret에는 토큰, 비밀번호, 키가 포함될 수 있어 매우 민감합니다.

이 권한은 꼭 필요한 워크로드에만 제한적으로 부여해야 합니다. 일반 서비스 계정에는 Secret 조회 권한을 기본값처럼 주지 않는 편이 안전합니다.

잠재적 영향

  • 파드가 비밀번호, 토큰, 키 같은 민감한 정보를 읽을 수 있습니다.
  • 침해된 워크로드가 다른 시스템으로 추가 이동할 수 있습니다.
  • Secret 접근 주체가 많아질수록 사고 추적이 어려워집니다.

해결 방법

  • ServiceAccount에 연결된 Role과 ClusterRole에서 불필요한 Secret 읽기 권한을 제거하세요.
  • Secret 접근이 필요한 워크로드만 전용 ServiceAccount로 분리하세요.
  • RBAC 점검 시 resources: ["secrets"]와 읽기 동사를 별도 고위험 항목으로 관리하세요.

예시

예제의 testsa 서비스 계정은 assembly-prod 네임스페이스에 별도로 생성해야 합니다. Secret의 update 권한도 자격 증명 변조에 쓰일 수 있으므로 읽기 권한의 안전한 대안이 아닙니다.

변경 전

yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: testRoleVulnerable
rules:
  - apiGroups: [""]
    resources: ["secrets"]
    verbs: ["get", "watch", "list"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: testRoleBinding
subjects:
  - kind: ServiceAccount
    name: testsa
    namespace: assembly-prod
roleRef:
  kind: Role
  name: testRoleVulnerable
  apiGroup: rbac.authorization.k8s.io

변경 후

yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: testRoleWithBindingSafe
rules:
  - apiGroups: [""]
    resources: ["pods"]
    verbs: ["get", "list"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: assembly-prod
  name: bindingtestRoleWithBindingSafe
subjects:
  - kind: ServiceAccount
    name: testsa
    namespace: assembly-prod
roleRef:
  kind: Role
  name: testRoleWithBindingSafe
  apiGroup: rbac.authorization.k8s.io

설명:

  • 변경 전: ServiceAccount에 Secret 읽기 권한을 연결해 민감한 자격 증명 접근을 허용합니다.
  • 변경 후: 이 역할은 Secret 대신 파드 조회 권한만 부여합니다. 다른 역할 바인딩을 통해 Secret 권한이 남아 있지 않은지도 확인하세요.

참조