k8s: dont mount service account tokens to apps

Signed-off-by: Pascal Sthamer <10992664+P4sca1@users.noreply.github.com>
This commit is contained in:
Pascal Sthamer
2025-11-17 08:30:01 +01:00
parent 17ba84c2eb
commit b69afd630b
2 changed files with 13 additions and 6 deletions
+7 -3
View File
@@ -1426,6 +1426,9 @@ func deployK8sWorker(image string, identifier string, env []string) error {
}
replicaNumberInt32 := int32(replicaNumber)
// worker makes authenticated requests to the k8s api to create app deployments.
// Therefore, it needs to have access to the service account token.
automountServiceAccountToken := true
deployment := &appsv1.Deployment{
ObjectMeta: metav1.ObjectMeta{
@@ -1445,9 +1448,10 @@ func deployK8sWorker(image string, identifier string, env []string) error {
Containers: []corev1.Container{
containerAttachment,
},
DNSPolicy: corev1.DNSClusterFirst,
ServiceAccountName: workerServiceAccountName,
SecurityContext: podSecurityContext,
DNSPolicy: corev1.DNSClusterFirst,
ServiceAccountName: workerServiceAccountName,
AutomountServiceAccountToken: &automountServiceAccountToken,
SecurityContext: podSecurityContext,
},
},
},
+6 -3
View File
@@ -625,6 +625,8 @@ func deployk8sApp(image string, identifier string, env []string) error {
}
replicaNumberInt32 := int32(replicaNumber)
// apps do not need access the k8s api.
automountServiceAccountToken := false
deployment := &appsv1.Deployment{
ObjectMeta: metav1.ObjectMeta{
@@ -656,9 +658,10 @@ func deployk8sApp(image string, identifier string, env []string) error {
Resources: buildResourcesFromEnv(),
},
},
DNSPolicy: corev1.DNSClusterFirst,
ServiceAccountName: appServiceAccountName,
SecurityContext: podSecurityContext,
DNSPolicy: corev1.DNSClusterFirst,
ServiceAccountName: appServiceAccountName,
AutomountServiceAccountToken: &automountServiceAccountToken,
SecurityContext: podSecurityContext,
},
},
},