A projected ServiceAccount token can be bound to a Pod, limited to an audience, and rotated by the kubelet before expiry. An application that reads the token file only at startup can still present an expired token later. The receiving service must validate the audience and issuer rather than treating any signed cluster token as authorization. A static long-lived token Secret does not provide the same lifecycle.
Projected identity tokens: reopen the file and verify its audience
Operational decision
A settlement exporter uses a projected token to authenticate to an internal broker. Request only the broker audience and a bounded expiration in the Pod volume, then configure the client to reopen the token path before exchange or after a rejected request. The fragment shows the projected source; a consuming container still needs a read-only mount and the broker must verify the audience. In a disposable Pod, inspect token expiry without logging the token, keep the Pod running past the original expiry, and prove that a subsequent broker call uses a renewed token. Send the same token to a test audience that should reject it. Delete the Pod and verify its bound identity can no longer be used after the platform's revocation behavior takes effect. Record token age, refresh failures, and authentication errors by workload identity. If a library caches the file contents indefinitely, replace or wrap that behavior before shortening token lifetimes.
apiVersion: v1
kind: Pod
metadata:
name: settlement-exporter-identity-check
namespace: settlement
spec:
automountServiceAccountToken: false
serviceAccountName: settlement-exporter
containers:
- name: exporter
image: registry.internal/settlement-exporter:approved-build
volumeMounts:
- name: broker-identity
mountPath: /var/run/broker-identity
readOnly: true
volumes:
- name: broker-identity
projected:
sources:
- serviceAccountToken:
path: token
audience: settlement-broker
expirationSeconds: 2400Cost and verification
Shorter token lives reduce exposure after theft but increase dependence on token refresh and issuer availability. Frequent reads of a local projected file are cheap; repeated remote token exchanges and broker authentication can add latency and rate-limit pressure. Measure refresh lead time, expiry margin, audience rejection, and how quickly the client recovers after a temporary issuer outage. The token belongs to the Pod identity, so preserving it beyond the Pod's lifetime is a design error.
Common Mistakes
- Do not cache token bytes for the entire container lifetime.
- Do not assume a valid signature means the token has the intended audience.
- Do not substitute a permanent ServiceAccount token Secret for a rotating projection without accepting the added risk.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Service account tokens: mount only when the workload needs Kubernetes API access
- Federated workload identity: replace standing cloud keys with scoped trust
- Secret access: audit workload creation as an indirect read permission
- Credential incident response: revoke access before rebuilding trust
