Skip to main content

More Info:

Service account tokens should be mounted into pods only when needed (automountServiceAccountToken=false by default). Auto-mounting tokens everywhere expands credential exposure if a pod is compromised.

Risk Level

Medium

Address

Compliance, Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.