Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Cloud Kubernetes permissions: scope the service account to its reads

Last updated: 1 Oct 20264 min read
tutorial
IntermediateBy AITrove Editorial

A configuration starter that reads cluster objects needs Kubernetes API permission; the workload should receive only the verbs and namespace it uses.

Name the API dependency

A Boot service imports a ConfigMap through Spring Cloud Kubernetes. The client runs under the pod's service account, so a missing RoleBinding can make startup or refresh fail. A broad cluster-reader grant may make the example work but grants much more than a single service needs. Use a namespaced Role for the required resource types and verbs. Config import defines what must be read; reload may add watch access.

Separate ConfigMaps from Secrets

A service that reads only a ConfigMap should not get secret access by default. If secrets are needed, identify the exact consumption path and test it with the deployment service account. List and watch can expose multiple objects in a namespace, so use a dedicated namespace or a carefully tested resource-name restriction where the API operation permits it.

Prove denial is contained

Start the deployment with get permission but no watch and observe whether startup works while reload fails as expected. Remove ConfigMap access and assert a required import stops startup. The test must run inside the intended namespace; a developer's local kubeconfig can hide a missing service-account grant.

Implementation sketch

yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: dispatch-config-reader
  namespace: dispatch
rules:
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["get", "list", "watch"]

Cost and verification

A namespaced Role limits exposure, but watches still consume API connections and events. Remove unused verbs and resources after measuring the actual client behavior.

Common Mistakes

  • Do not bind a cluster-wide reader role to one configuration consumer.
  • Do not grant secret reads when the service only uses ConfigMaps.
  • Do not validate permissions with a developer kubeconfig instead of the pod service account.

Read next

Spring Cloud Kubernetes config import: make source precedence explicit, Spring Cloud Kubernetes reload: decide which changes need a restart, Spring Boot Kubernetes probes: separate startup, readiness and liveness.

spring
spring-boot
production
kubernetes-config-rbac
Storage details