🎯 Lesson Objective
Understand authentication and authorization in Kubernetes, how to use RBAC for authorization, Pod Security Standards to replace PodSecurityPolicy (removed K8s 1.25), and important Admission Controllers.
1. Authentication in Kubernetes
Kubernetes does not have user management built-in. Instead, kube-apiserver supports many authentication methods:
- X.509 Client Certificates: kubeconfig uses client cert, most common
- Bearer Tokens: ServiceAccount tokens, OIDC tokens
- OIDC (OpenID Connect): integrates with Dex, Keycloak, Auth0, Google, Azure AD
- Webhook: delegate authentication to external service
2. Users vs ServiceAccounts
- Users: human identities — no resources in Kubernetes, managed externally (certs, OIDC)
- ServiceAccounts: machine identities — Kubernetes resource, used for Pods
# Tạo ServiceAccount kubectl create serviceaccount my-app-sa -n productionXem ServiceAccount
kubectl get serviceaccounts -n production kubectl describe serviceaccount my-app-sa -n production
# Pod dùng ServiceAccount
apiVersion: v1
kind: Pod
spec:
serviceAccountName: my-app-sa
# Token tự động mounted tại /var/run/secrets/kubernetes.io/serviceaccount/token
Projected Service Account Tokens (K8s 1.22+): short-term tokens, auto-rotate, bounded audience — much more secure than old long-lived tokens.
3. RBAC — Role-Based Access Control
3.1 Roles and ClusterRoles
# Role: chỉ áp dụng trong 1 namespace
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: pod-reader
namespace: production
rules:
- apiGroups: [""] # "" = core API group
resources: ["pods"]
verbs: ["get", "watch", "list"]
- apiGroups: ["apps"]
resources: ["deployments"]
verbs: ["get", "list", "create", "update", "patch", "delete"]
---
# ClusterRole: áp dụng trên toàn cluster
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: node-reader
rules:
- apiGroups: [""]
resources: ["nodes"]
verbs: ["get", "list", "watch"]
3.2 RoleBindings and ClusterRoleBindings__HTMLTAG_112___
# Bind role cho ServiceAccount
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-pods-binding
namespace: production
subjects:
- kind: ServiceAccount
name: my-app-sa
namespace: production
- kind: User # bind cho human user
name: jane
apiGroup: rbac.authorization.k8s.io
- kind: Group
name: developers
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: Role
name: pod-reader
apiGroup: rbac.authorization.k8s.io
# Test permissions
kubectl auth can-i get pods --as=jane -n production
kubectl auth can-i delete deployments --as=system:serviceaccount:production:my-app-sa
Xem permissions của current user
kubectl auth can-i --list
# Bind role cho ServiceAccount
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-pods-binding
namespace: production
subjects:
- kind: ServiceAccount
name: my-app-sa
namespace: production
- kind: User # bind cho human user
name: jane
apiGroup: rbac.authorization.k8s.io
- kind: Group
name: developers
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: Role
name: pod-reader
apiGroup: rbac.authorization.k8s.io
# Test permissions
kubectl auth can-i get pods --as=jane -n production
kubectl auth can-i delete deployments --as=system:serviceaccount:production:my-app-sa
Xem permissions của current user
kubectl auth can-i --list
3.3 Least Privilege Principle
# CI/CD ServiceAccount: chỉ cần deploy, không cần đọc secrets
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: cicd-deployer
namespace: production
rules:
- apiGroups: ["apps"]
resources: ["deployments"]
verbs: ["get", "list", "create", "update", "patch"]
resourceNames: ["my-app"] # giới hạn chỉ deployment cụ thể
- apiGroups: [""]
resources: ["services", "configmaps"]
verbs: ["get", "list"]
4. Pod Security Standards (PSS) — Replace PodSecurityPolicy
PodSecurityPolicy (PSP) has been completely removed in K8s 1.25. Replaced by Pod Security Standards:
4.1 Three levels of security
- Privileged: no restrictions. Only used for system components, cluster-wide controllers
- Baseline: prevents common escalations. Suitable for most applications. Block: privileged containers, hostPath, hostNetwork, hostPID
- Restricted: hardened security. Requirements: non-root user, non-root group, drop ALL capabilities, seccompProfile RuntimeDefault/Localhost, no hostPath
4.2 Pod Security Admission (PSA)
# Áp dụng PSA bằng namespace labels kubectl label namespace production \ pod-security.kubernetes.io/enforce=restricted \ # enforce: reject violating pods pod-security.kubernetes.io/warn=restricted \ # warn: allow nhưng warning pod-security.kubernetes.io/audit=restricted # audit: log violationsKiểm tra
kubectl get namespace production --show-labels
# Pod tuân thủ Restricted level
apiVersion: v1
kind: Pod
spec:
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 3000
fsGroup: 2000
seccompProfile:
type: RuntimeDefault
containers:
- name: app
image: myapp:v1
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
5. Admission Controllers
Admission controllers intercept requests to the API server after authentication/authorization. There are 2 types:
- Mutating: change object (eg inject sidecar, set default values)
- Validating: only approve/deny (eg: PSA, ResourceQuota)
# Xem admission plugins được enable kube-apiserver --help | grep enable-admission-pluginsDefault plugins quan trọng:
- NamespaceLifecycle: ngăn tạo resource trong namespace đang terminating
- ResourceQuota: enforce quotas
- LimitRanger: áp dụng LimitRange defaults
- PodSecurity: Pod Security Admission
- ServiceAccount: auto-inject token mount
6. Admission Webhook
# ValidatingWebhookConfiguration: gọi external service để validate
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingWebhookConfiguration
metadata:
name: my-validator
webhooks:
- name: validate.example.com
clientConfig:
service:
name: my-validator-service
namespace: system
path: /validate
rules:
- apiGroups: ["apps"]
apiVersions: ["v1"]
operations: ["CREATE", "UPDATE"]
resources: ["deployments"]
admissionReviewVersions: ["v1"]
sideEffects: None
Summary
- Kubernetes has no user management — uses X.509 certs, OIDC
- ServiceAccounts: machine identities, projected tokens (short-lived)
- RBAC: Role/ClusterRole + RoleBinding/ClusterRoleBinding
- Least privilege: only grant the minimum necessary permission
- PSP removed K8s 1.25 → use Pod Security Standards (PSA)
- PSA levels: Privileged, Baseline (recommended default), Restricted (production)