A configuration starter that reads cluster objects needs Kubernetes API permission; the workload should receive only the verbs and namespace it uses.
Spring Cloud Kubernetes permissions: scope the service account to its reads
Name the API dependency
A Boot service imports a ConfigMap through Spring Cloud Kubernetes. The client runs under the pod's service account, so a missing RoleBinding can make startup or refresh fail. A broad cluster-reader grant may make the example work but grants much more than a single service needs. Use a namespaced Role for the required resource types and verbs. Config import defines what must be read; reload may add watch access.
Separate ConfigMaps from Secrets
A service that reads only a ConfigMap should not get secret access by default. If secrets are needed, identify the exact consumption path and test it with the deployment service account. List and watch can expose multiple objects in a namespace, so use a dedicated namespace or a carefully tested resource-name restriction where the API operation permits it.
Prove denial is contained
Start the deployment with get permission but no watch and observe whether startup works while reload fails as expected. Remove ConfigMap access and assert a required import stops startup. The test must run inside the intended namespace; a developer's local kubeconfig can hide a missing service-account grant.
Implementation sketch
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: dispatch-config-reader
namespace: dispatch
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list", "watch"]Cost and verification
A namespaced Role limits exposure, but watches still consume API connections and events. Remove unused verbs and resources after measuring the actual client behavior.
Common Mistakes
- Do not bind a cluster-wide reader role to one configuration consumer.
- Do not grant secret reads when the service only uses ConfigMaps.
- Do not validate permissions with a developer kubeconfig instead of the pod service account.
Read next
Spring Cloud Kubernetes config import: make source precedence explicit, Spring Cloud Kubernetes reload: decide which changes need a restart, Spring Boot Kubernetes probes: separate startup, readiness and liveness.
