Chuyển đến nội dung chính

LESSON 23: AUTHENTICATION AND AUTHORIZATION

Authentication, ServiceAccounts, RBAC in Kubernetes. Pod Security Standards (PSS) and Pod Security Admission (PSA) replace PodSecurityPolicy (removed K8s 1.25). Admission Controllers.

🔒 DevSecOps — Lesson 23 LESSON 23: AUTHENTICATION AND AUTHORIZATION

KUBERNETES: FROM BASIC TO ADVANCED

Module 6: Security

xdev.asia

🎯 Lesson Objective

Understand authentication and authorization in Kubernetes, how to use RBAC for authorization, Pod Security Standards to replace PodSecurityPolicy (removed K8s 1.25), and important Admission Controllers.

1. Authentication in Kubernetes

Kubernetes does not have user management built-in. Instead, kube-apiserver supports many authentication methods:

  • X.509 Client Certificates: kubeconfig uses client cert, most common
  • Bearer Tokens: ServiceAccount tokens, OIDC tokens
  • OIDC (OpenID Connect): integrates with Dex, Keycloak, Auth0, Google, Azure AD
  • Webhook: delegate authentication to external service

2. Users vs ServiceAccounts

  • Users: human identities — no resources in Kubernetes, managed externally (certs, OIDC)
  • ServiceAccounts: machine identities — Kubernetes resource, used for Pods
# Tạo ServiceAccount
kubectl create serviceaccount my-app-sa -n production

Xem ServiceAccount

kubectl get serviceaccounts -n production kubectl describe serviceaccount my-app-sa -n production

# Pod dùng ServiceAccount
apiVersion: v1
kind: Pod
spec:
  serviceAccountName: my-app-sa
  # Token tự động mounted tại /var/run/secrets/kubernetes.io/serviceaccount/token

Projected Service Account Tokens (K8s 1.22+): short-term tokens, auto-rotate, bounded audience — much more secure than old long-lived tokens.

3. RBAC — Role-Based Access Control

3.1 Roles and ClusterRoles

# Role: chỉ áp dụng trong 1 namespace
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: pod-reader
  namespace: production
rules:
- apiGroups: [""]           # "" = core API group
  resources: ["pods"]
  verbs: ["get", "watch", "list"]
- apiGroups: ["apps"]
  resources: ["deployments"]
  verbs: ["get", "list", "create", "update", "patch", "delete"]
---
# ClusterRole: áp dụng trên toàn cluster
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: node-reader
rules:
- apiGroups: [""]
  resources: ["nodes"]
  verbs: ["get", "list", "watch"]

3.2 RoleBindings and ClusterRoleBindings__HTMLTAG_112___
# Bind role cho ServiceAccount
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: read-pods-binding
  namespace: production
subjects:
- kind: ServiceAccount
  name: my-app-sa
  namespace: production
- kind: User           # bind cho human user
  name: jane
  apiGroup: rbac.authorization.k8s.io
- kind: Group
  name: developers
  apiGroup: rbac.authorization.k8s.io
roleRef:
  kind: Role
  name: pod-reader
  apiGroup: rbac.authorization.k8s.io
# Test permissions
kubectl auth can-i get pods --as=jane -n production
kubectl auth can-i delete deployments --as=system:serviceaccount:production:my-app-sa

Xem permissions của current user

kubectl auth can-i --list

3.3 Least Privilege Principle

# CI/CD ServiceAccount: chỉ cần deploy, không cần đọc secrets
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: cicd-deployer
  namespace: production
rules:
- apiGroups: ["apps"]
  resources: ["deployments"]
  verbs: ["get", "list", "create", "update", "patch"]
  resourceNames: ["my-app"]  # giới hạn chỉ deployment cụ thể
- apiGroups: [""]
  resources: ["services", "configmaps"]
  verbs: ["get", "list"]

4. Pod Security Standards (PSS) — Replace PodSecurityPolicy

PodSecurityPolicy (PSP) has been completely removed in K8s 1.25. Replaced by Pod Security Standards:

4.1 Three levels of security

  • Privileged: no restrictions. Only used for system components, cluster-wide controllers
  • Baseline: prevents common escalations. Suitable for most applications. Block: privileged containers, hostPath, hostNetwork, hostPID
  • Restricted: hardened security. Requirements: non-root user, non-root group, drop ALL capabilities, seccompProfile RuntimeDefault/Localhost, no hostPath

4.2 Pod Security Admission (PSA)

# Áp dụng PSA bằng namespace labels
kubectl label namespace production \
  pod-security.kubernetes.io/enforce=restricted \        # enforce: reject violating pods
  pod-security.kubernetes.io/warn=restricted \           # warn: allow nhưng warning
  pod-security.kubernetes.io/audit=restricted            # audit: log violations

Kiểm tra

kubectl get namespace production --show-labels

# Pod tuân thủ Restricted level
apiVersion: v1
kind: Pod
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 1000
    runAsGroup: 3000
    fsGroup: 2000
    seccompProfile:
      type: RuntimeDefault
  containers:
  - name: app
    image: myapp:v1
    securityContext:
      allowPrivilegeEscalation: false
      readOnlyRootFilesystem: true
      capabilities:
        drop: ["ALL"]

5. Admission Controllers

Admission controllers intercept requests to the API server after authentication/authorization. There are 2 types:

  • Mutating: change object (eg inject sidecar, set default values)
  • Validating: only approve/deny (eg: PSA, ResourceQuota)
# Xem admission plugins được enable
kube-apiserver --help | grep enable-admission-plugins

Default plugins quan trọng:

- NamespaceLifecycle: ngăn tạo resource trong namespace đang terminating

- ResourceQuota: enforce quotas

- LimitRanger: áp dụng LimitRange defaults

- PodSecurity: Pod Security Admission

- ServiceAccount: auto-inject token mount

6. Admission Webhook

# ValidatingWebhookConfiguration: gọi external service để validate
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingWebhookConfiguration
metadata:
  name: my-validator
webhooks:
- name: validate.example.com
  clientConfig:
    service:
      name: my-validator-service
      namespace: system
      path: /validate
  rules:
  - apiGroups: ["apps"]
    apiVersions: ["v1"]
    operations: ["CREATE", "UPDATE"]
    resources: ["deployments"]
  admissionReviewVersions: ["v1"]
  sideEffects: None

Summary

  • Kubernetes has no user management — uses X.509 certs, OIDC
  • ServiceAccounts: machine identities, projected tokens (short-lived)
  • RBAC: Role/ClusterRole + RoleBinding/ClusterRoleBinding
  • Least privilege: only grant the minimum necessary permission
  • PSP removed K8s 1.25 → use Pod Security Standards (PSA)
  • PSA levels: Privileged, Baseline (recommended default), Restricted (production)