Merge pull request #1881 from PROCYDE/k8s-service-account-token-mounting
k8s: dont mount service account tokens to apps
This commit is contained in:
@@ -1558,15 +1558,6 @@ app:
|
|||||||
##
|
##
|
||||||
annotations: {}
|
annotations: {}
|
||||||
## @param app.serviceAccount.automountServiceAccountToken Automount service account token for the app service account
|
## @param app.serviceAccount.automountServiceAccountToken Automount service account token for the app service account
|
||||||
## NOTE: You likely want to allow access to cluster-proxies, e.g:
|
|
||||||
## extraEgress:
|
|
||||||
## - to:
|
|
||||||
## - namespaceSelector:
|
|
||||||
## matchLabels:
|
|
||||||
## kubernetes.io/metadata.name: istio-system
|
|
||||||
## podSelector:
|
|
||||||
## matchLabels:
|
|
||||||
## istio: pilot
|
|
||||||
##
|
##
|
||||||
automountServiceAccountToken: true
|
automountServiceAccountToken: true
|
||||||
## @param app.serviceAccount.imagePullSecrets Add image pull secrets to the app service account
|
## @param app.serviceAccount.imagePullSecrets Add image pull secrets to the app service account
|
||||||
|
|||||||
@@ -1426,6 +1426,9 @@ func deployK8sWorker(image string, identifier string, env []string) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
replicaNumberInt32 := int32(replicaNumber)
|
replicaNumberInt32 := int32(replicaNumber)
|
||||||
|
// worker makes authenticated requests to the k8s api to create app deployments.
|
||||||
|
// Therefore, it needs to have access to the service account token.
|
||||||
|
automountServiceAccountToken := true
|
||||||
|
|
||||||
deployment := &appsv1.Deployment{
|
deployment := &appsv1.Deployment{
|
||||||
ObjectMeta: metav1.ObjectMeta{
|
ObjectMeta: metav1.ObjectMeta{
|
||||||
@@ -1445,9 +1448,10 @@ func deployK8sWorker(image string, identifier string, env []string) error {
|
|||||||
Containers: []corev1.Container{
|
Containers: []corev1.Container{
|
||||||
containerAttachment,
|
containerAttachment,
|
||||||
},
|
},
|
||||||
DNSPolicy: corev1.DNSClusterFirst,
|
DNSPolicy: corev1.DNSClusterFirst,
|
||||||
ServiceAccountName: workerServiceAccountName,
|
ServiceAccountName: workerServiceAccountName,
|
||||||
SecurityContext: podSecurityContext,
|
AutomountServiceAccountToken: &automountServiceAccountToken,
|
||||||
|
SecurityContext: podSecurityContext,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -625,6 +625,8 @@ func deployk8sApp(image string, identifier string, env []string) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
replicaNumberInt32 := int32(replicaNumber)
|
replicaNumberInt32 := int32(replicaNumber)
|
||||||
|
// apps do not need access the k8s api.
|
||||||
|
automountServiceAccountToken := false
|
||||||
|
|
||||||
deployment := &appsv1.Deployment{
|
deployment := &appsv1.Deployment{
|
||||||
ObjectMeta: metav1.ObjectMeta{
|
ObjectMeta: metav1.ObjectMeta{
|
||||||
@@ -656,9 +658,10 @@ func deployk8sApp(image string, identifier string, env []string) error {
|
|||||||
Resources: buildResourcesFromEnv(),
|
Resources: buildResourcesFromEnv(),
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
DNSPolicy: corev1.DNSClusterFirst,
|
DNSPolicy: corev1.DNSClusterFirst,
|
||||||
ServiceAccountName: appServiceAccountName,
|
ServiceAccountName: appServiceAccountName,
|
||||||
SecurityContext: podSecurityContext,
|
AutomountServiceAccountToken: &automountServiceAccountToken,
|
||||||
|
SecurityContext: podSecurityContext,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user