Hands-on Lab·Certified Kubernetes Security Specialist
ServiceAccount Tokens and automountServiceAccountToken
The competency says exercise caution in using service accounts, and the caution has three parts: stop mounting credentials into workloads that never call the API, give the ones that do their own identity, and know which token type you are looking at. This guide does all three and measures each.
Cluster Hardening Guide 11 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 17 min
- Reviewed25 August 2026
Written against the versions above. Projected tokens are the default since 1.24 - audience-bound and expiring. Auto-created `kubernetes.io/service-account-token` Secrets ended in the same release; any that exist were made by hand.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 9 - the grants these identities carry.
-
The credential every Pod gets without asking
-
Turn it off where it is not needed
-
A dedicated identity for the workload that does need one
-
The token type that should not exist any more