Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A large enterprise is implementing a new Kubernetes cluster with multiple development teams. Each team requires access to specific cloud provider resources (e.g., S3 buckets, database services) from their applications running in Pods. The security team insists on using a solution that avoids embedding long-lived credentials directly into Pods or container images. Which security pattern should they implement to securely grant Pods access to these external cloud resources?
- ADistributing cloud provider access keys as Kubernetes Secrets.
- BUsing a shared service account with full administrative privileges for all Pods.
- CMounting cloud provider credential files directly into Pods via ConfigMaps.
- DLeveraging Workload Identity (or equivalent cloud provider feature).
Show answer & explanationAnswer & explanation
Correct answer: D. Leveraging Workload Identity (or equivalent cloud provider feature).
Workload Identity (or similar cloud provider features like IAM Roles for Service Accounts in AWS, Workload Identity Federations in GCP, or Managed Identities in Azure) allows Kubernetes Service Accounts to assume cloud provider IAM roles, granting Pods temporary, fine-grained access to external resources without storing long-lived credentials.
Why the other options are wrong
- A. Storing access keys as Kubernetes Secrets still involves managing long-lived credentials and risks exposure if the secret is compromised.
- B. Using a shared service account with administrative privileges violates the principle of least privilege and creates a significant security vulnerability.
- C. ConfigMaps are not designed for sensitive data and mounting credential files directly is insecure, as they are not encrypted and can be easily exfiltrated.
Workload Identity
A security pattern that allows Kubernetes Service Accounts to act as identities for cloud provider IAM roles, enabling Pods to securely access external cloud resources without storing long-lived credentials.
- Maps Kubernetes Service Accounts to cloud provider IAM roles.
- Provides temporary, fine-grained access to cloud resources.
- Eliminates the need to embed cloud credentials in Pods or images.
Memory trick: Workload Identity: Your Pod is the key, the cloud is the lock.