Skip to main content

More Info:

The default service account should not be used to ensure that rights granted to applications can be more easily audited and reviewed.

Risk Level

Medium

Address

Security

Compliance Standards

  • CIS Kubernetes

Triage and Remediation

Remediation

Using Console

For each namespace in the cluster, review the rights assigned to the default serviceaccount and ensure that it has no roles or cluster roles bound to it apart from thedefaults.Additionally ensure that the automountServiceAccountToken: false setting is in placefor each default service account.

Additional Reading: