Skip to content

Commit 24cbaa1

Browse files
feat(driver-kubernetes): disable service account token auto-mounting (#1298)
Disables automountServiceAccountToken in sandbox pods for security hardening. Sandbox pods should not have access to the Kubernetes API by default. Adds test case to verify the pod spec includes the disabled setting. Signed-off-by: Derek Carr <decarr@redhat.com>
1 parent ca63841 commit 24cbaa1

1 file changed

Lines changed: 27 additions & 0 deletions

File tree

  • crates/openshell-driver-kubernetes/src

‎crates/openshell-driver-kubernetes/src/driver.rs‎

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1064,6 +1064,13 @@ fn sandbox_template_to_k8s(
10641064
}
10651065
}
10661066

1067+
// Disable service account token auto-mounting for security hardening.
1068+
// Sandbox pods should not have access to the Kubernetes API by default.
1069+
spec.insert(
1070+
"automountServiceAccountToken".to_string(),
1071+
serde_json::json!(false),
1072+
);
1073+
10671074
let mut container = serde_json::Map::new();
10681075
container.insert("name".to_string(), serde_json::json!("agent"));
10691076
// Use template image if provided, otherwise fall back to default
@@ -2116,6 +2123,26 @@ mod tests {
21162123
);
21172124
}
21182125

2126+
#[test]
2127+
fn automount_service_account_token_is_disabled() {
2128+
let pod_template = {
2129+
let params = SandboxPodParams::default();
2130+
sandbox_template_to_k8s(
2131+
&SandboxTemplate::default(),
2132+
false,
2133+
&std::collections::HashMap::new(),
2134+
true,
2135+
&params,
2136+
)
2137+
};
2138+
2139+
assert_eq!(
2140+
pod_template["spec"]["automountServiceAccountToken"],
2141+
serde_json::json!(false),
2142+
"service account token auto-mounting must be disabled for security hardening"
2143+
);
2144+
}
2145+
21192146
#[test]
21202147
fn platform_config_bool_extracts_value() {
21212148
let template = SandboxTemplate {

0 commit comments

Comments
 (0)