learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Least Privilege (CKS)

Shrink every identity to exactly what it needs, starting with ServiceAccounts.

An interactive Kubernetes lesson: 19 steps, about 30 minutes, on a live simulation in your browser.

The shop runs in the namespace shop: customers reach web, and web calls api. Neither manifest mentions a ServiceAccount.

That does not mean they have none. Every namespace has a ServiceAccount named default, and a pod that names no other runs as it. The kubelet then mounts a signed token for that account into every container, at a fixed path.

What you will learn

  1. Every pod is somebody

    • A token in every pod: Every pod runs as a ServiceAccount. Name none and it is default, with its token sitting in a file inside the container.
    • What the token opens
    • Ask what an identity can do: kubectl auth can-i --list --as=<identity> shows what a stolen credential is worth. Run it before an attacker does.
  2. One small identity each

    • Give web its own ServiceAccount: One ServiceAccount per workload, one Role listing only what that workload calls. The default account gets nothing.
    • The same attack, a smaller identity: Least privilege does not stop the break-in. It decides what the break-in is worth.
    • No token at all: Most workloads never call the Kubernetes API. Turn token mounting off for them, and there is nothing to steal.
    • Tokens that expire: A pod's token is bound to that pod and expires within the hour. A token stored in a Secret lives until someone remembers to delete it.
  3. Grants that give it all away

    • The pipeline is cluster-admin: A ClusterRoleBinding applies in every namespace that exists or ever will. Bound to cluster-admin, one leaked token is the whole cluster.
    • Shrink it to the job: The Role says what. The RoleBinding's namespace says where. The subject can come from any namespace.
    • "Only list, not get": On secrets, get, list and watch each mean "can read every value". Grant get on named Secrets, or nothing.
    • Break it: exec borrows an identity: pods/exec in a namespace lends you every ServiceAccount that runs there. So does permission to create pods.
    • Break it: three verbs that mean admin: impersonate, escalate and bind are permission to change your own permissions. Whoever holds one is an admin who has not used it yet.
  4. People

    • One job description, one namespace: ClusterRole plus RoleBinding: a job description written once, granted one namespace at a time.
    • The group RBAC cannot touch: system:masters skips RBAC and cannot be revoked. Everyday access should come from bindings, because a binding can be deleted.
  5. At exam speed

    • RBAC in four commands
    • Drill: check an identity
    • Drill: bind a Role to a ServiceAccount
  6. Recap & playground

    • Cheat sheet
    • Playground