Vincent von Büren was refactoring an old Helm chart when he spotted a debug log line printing a Kubernetes ServiceAccount token to stdout — still running in production.
He decoded it: no audience restrictions, one-year expiry. "My stomach turned. I knew this could be a serious security incident."
In this episode, Vincent breaks down:
- What's actually inside a ServiceAccount JWT
- Why default tokens enable replay attacks
- Projected tokens — the solution that's been available since 1.20, but why most teams haven't switched
- Practical steps to reduce exposure
Watch (or listen to) it here: https://ku.bz/LTnB_Ntbc
🌟 This episode is brought to you by LearnKube — comprehensive Kubernetes training. https://learnkube.com/training
With @Birthmarkb
Post #1701
228
Forwarded from KubeFM