Lab
ServiceAccount Token Hardening
Most pods never call the Kubernetes API, yet by default every pod gets a mounted API token an attacker can steal. Give a workload its own ServiceAccount and turn token auto-mount off.
Your mission
Every pod is assigned a ServiceAccount, and by default Kubernetes mounts that
account's API token into the container at
/var/run/secrets/kubernetes.io/serviceaccount/. Most workloads never call the API —
so that token is pure attack surface: steal it from a compromised container and you
can talk to the API server as that account.
CKS wants two habits: give a workload its own ServiceAccount (not default), and
turn off token auto-mount unless the app genuinely needs it. You'll do both in the
apps namespace (already created).
kubectl config set-context --current --namespace=appsSkills you'll put into practice
securityserviceaccountrbaccks