diff --git a/functions/onprem/orborus/orborus.go b/functions/onprem/orborus/orborus.go index b5bcf486..365f368a 100755 --- a/functions/onprem/orborus/orborus.go +++ b/functions/onprem/orborus/orborus.go @@ -1426,6 +1426,9 @@ func deployK8sWorker(image string, identifier string, env []string) error { } replicaNumberInt32 := int32(replicaNumber) + // worker makes authenticated requests to the k8s api to create app deployments. + // Therefore, it needs to have access to the service account token. + automountServiceAccountToken := true deployment := &appsv1.Deployment{ ObjectMeta: metav1.ObjectMeta{ @@ -1445,9 +1448,10 @@ func deployK8sWorker(image string, identifier string, env []string) error { Containers: []corev1.Container{ containerAttachment, }, - DNSPolicy: corev1.DNSClusterFirst, - ServiceAccountName: workerServiceAccountName, - SecurityContext: podSecurityContext, + DNSPolicy: corev1.DNSClusterFirst, + ServiceAccountName: workerServiceAccountName, + AutomountServiceAccountToken: &automountServiceAccountToken, + SecurityContext: podSecurityContext, }, }, }, diff --git a/functions/onprem/worker/worker.go b/functions/onprem/worker/worker.go index 09c95187..caa160b3 100644 --- a/functions/onprem/worker/worker.go +++ b/functions/onprem/worker/worker.go @@ -625,6 +625,8 @@ func deployk8sApp(image string, identifier string, env []string) error { } replicaNumberInt32 := int32(replicaNumber) + // apps do not need access the k8s api. + automountServiceAccountToken := false deployment := &appsv1.Deployment{ ObjectMeta: metav1.ObjectMeta{ @@ -656,9 +658,10 @@ func deployk8sApp(image string, identifier string, env []string) error { Resources: buildResourcesFromEnv(), }, }, - DNSPolicy: corev1.DNSClusterFirst, - ServiceAccountName: appServiceAccountName, - SecurityContext: podSecurityContext, + DNSPolicy: corev1.DNSClusterFirst, + ServiceAccountName: appServiceAccountName, + AutomountServiceAccountToken: &automountServiceAccountToken, + SecurityContext: podSecurityContext, }, }, },