pod-serviceaccount-name
Running under the namespace default ServiceAccount makes every workload share one identity, so any permission granted to it reaches all of them and API audit records cannot be traced back to a single pod.
has(object.spec.serviceAccountName) && size(object.spec.serviceAccountName) > 0 && object.spec.serviceAccountName != "default"
spec.serviceAccountName must be set to a non-default service account.
Create a dedicated ServiceAccount holding only the permissions this workload needs and set spec.serviceAccountName to it. Field: spec.serviceAccountName.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: pod-serviceaccount-name
annotations:
kubeapt.io/uuid: "1e4e5442-122f-4dd9-86ce-a6104971b13b"
security.kubeapt.io/displayName: "Uses the Default ServiceAccount"
security.kubeapt.io/description: "Running under the namespace default ServiceAccount makes every workload share one identity, so any permission granted to it reaches all of them and API audit records cannot be traced back to a single pod."
security.kubeapt.io/resource: "Pods"
security.kubeapt.io/severity: "Low"
security.kubeapt.io/remediation: "Create a dedicated ServiceAccount holding only the permissions this workload needs and set spec.serviceAccountName to it. Field: spec.serviceAccountName."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
validations:
- expression: |
has(object.spec.serviceAccountName) && size(object.spec.serviceAccountName) > 0 && object.spec.serviceAccountName != "default"
message: |
spec.serviceAccountName must be set to a non-default service account.Save it as pod-serviceaccount-name.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./pod-serviceaccount-name.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name pod-serviceaccount-name -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name pod-serviceaccount-name -A