Back to Practice
Lab

ServiceAccount Token Hardening

Most pods never call the Kubernetes API, yet by default every pod gets a mounted API token an attacker can steal. Give a workload its own ServiceAccount and turn token auto-mount off.

Your mission

Every pod is assigned a ServiceAccount, and by default Kubernetes mounts that account's API token into the container at /var/run/secrets/kubernetes.io/serviceaccount/. Most workloads never call the API — so that token is pure attack surface: steal it from a compromised container and you can talk to the API server as that account.

CKS wants two habits: give a workload its own ServiceAccount (not default), and turn off token auto-mount unless the app genuinely needs it. You'll do both in the apps namespace (already created).

kubectl config set-context --current --namespace=apps

Skills you'll put into practice

securityserviceaccountrbaccks

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation