A pod service account is an identity
Every pod runs as an identity, and by default it may be one with more access than the workload needs.
That token is mounted into the container and is available to anything running there, including anything an attacker gets executing. Turning off automatic mounting where it is not needed, and scoping it tightly where it is, removes a well-used escalation path.
More on Kubernetes
- A container is isolation, not a tiny virtual machinePartitions, not buildings
- Kubernetes RBAC controls API actions, not what a running container can then doChecked at the hatch, not inside the room
- NetworkPolicy needs an enforcement engineHinges, but no gate
- Admission control can stop risky objects before they runStopped on the chute
- Privileged containers weaken the host boundaryThe floor is the boundary
- Mutable image tags can move underneath youSame ticket, different coat
