Least Privilege (CKS)
Shrink every identity to exactly what it needs, starting with ServiceAccounts.
An interactive Kubernetes lesson: 19 steps, about 30 minutes, on a live simulation in your browser.
The shop runs in the namespace shop: customers reach web, and web calls api. Neither manifest mentions a ServiceAccount.
That does not mean they have none. Every namespace has a ServiceAccount named default, and a pod that names no other runs as it. The kubelet then mounts a signed token for that account into every container, at a fixed path.
What you will learn
Every pod is somebody
- A token in every pod: Every pod runs as a ServiceAccount. Name none and it is default, with its token sitting in a file inside the container.
- What the token opens
- Ask what an identity can do: kubectl auth can-i --list --as=<identity> shows what a stolen credential is worth. Run it before an attacker does.
One small identity each
- Give web its own ServiceAccount: One ServiceAccount per workload, one Role listing only what that workload calls. The default account gets nothing.
- The same attack, a smaller identity: Least privilege does not stop the break-in. It decides what the break-in is worth.
- No token at all: Most workloads never call the Kubernetes API. Turn token mounting off for them, and there is nothing to steal.
- Tokens that expire: A pod's token is bound to that pod and expires within the hour. A token stored in a Secret lives until someone remembers to delete it.
Grants that give it all away
- The pipeline is cluster-admin: A ClusterRoleBinding applies in every namespace that exists or ever will. Bound to cluster-admin, one leaked token is the whole cluster.
- Shrink it to the job: The Role says what. The RoleBinding's namespace says where. The subject can come from any namespace.
- "Only list, not get": On secrets, get, list and watch each mean "can read every value". Grant get on named Secrets, or nothing.
- Break it: exec borrows an identity: pods/exec in a namespace lends you every ServiceAccount that runs there. So does permission to create pods.
- Break it: three verbs that mean admin: impersonate, escalate and bind are permission to change your own permissions. Whoever holds one is an admin who has not used it yet.
People
- One job description, one namespace: ClusterRole plus RoleBinding: a job description written once, granted one namespace at a time.
- The group RBAC cannot touch: system:masters skips RBAC and cannot be revoked. Everyday access should come from bindings, because a binding can be deleted.
At exam speed
- RBAC in four commands
- Drill: check an identity
- Drill: bind a Role to a ServiceAccount
Recap & playground
- Cheat sheet
- Playground