Skip to content

Allow ServiceAccount templates to set automountServiceAccountToken

Summary

NSA/DISA Hardening guides recommend to set automountServiceAccountToken: false for SAs and pods that don't require mounting and use of their token to talk with the kubernetes API.

This does not seem to be an available setting to toggle for SA templates within the Gitlab chart.

https://media.defense.gov/2022/Aug/29/2003066362/-1/-1/0/CTR_KUBERNETES_HARDENING_GUIDANCE_1.2_20220829.PDF