More Info:
The default service account should not be used to ensure that rights granted to applications can be more easily audited and reviewed.Risk Level
MediumAddress
SecurityCompliance Standards
- CIS Kubernetes
Triage and Remediation
- Remediation
Remediation
Using Console
Using Console
For each namespace in the cluster, review the rights assigned to the default serviceaccount and ensure that it has no roles or cluster roles bound to it apart from thedefaults.Additionally ensure that the automountServiceAccountToken: false setting is in placefor each default service account.

