Service Account Tokens: The Quiet Security Hole in Every Cluster
Service account tokens are mounted into every pod by default. Here's how automountServiceAccountToken, bound tokens, and workload identity close the hole.
Read the post1 post about workload-identity in the conndeck blog — field notes on local-first Kubernetes operations, GitOps, and production debugging.
Service account tokens are mounted into every pod by default. Here's how automountServiceAccountToken, bound tokens, and workload identity close the hole.
Read the post