Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Projected identity tokens: reopen the file and verify its audience

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

A projected ServiceAccount token can be bound to a Pod, limited to an audience, and rotated by the kubelet before expiry. An application that reads the token file only at startup can still present an expired token later. The receiving service must validate the audience and issuer rather than treating any signed cluster token as authorization. A static long-lived token Secret does not provide the same lifecycle.

Operational decision

A settlement exporter uses a projected token to authenticate to an internal broker. Request only the broker audience and a bounded expiration in the Pod volume, then configure the client to reopen the token path before exchange or after a rejected request. The fragment shows the projected source; a consuming container still needs a read-only mount and the broker must verify the audience. In a disposable Pod, inspect token expiry without logging the token, keep the Pod running past the original expiry, and prove that a subsequent broker call uses a renewed token. Send the same token to a test audience that should reject it. Delete the Pod and verify its bound identity can no longer be used after the platform's revocation behavior takes effect. Record token age, refresh failures, and authentication errors by workload identity. If a library caches the file contents indefinitely, replace or wrap that behavior before shortening token lifetimes.

yaml
apiVersion: v1
kind: Pod
metadata:
  name: settlement-exporter-identity-check
  namespace: settlement
spec:
  automountServiceAccountToken: false
  serviceAccountName: settlement-exporter
  containers:
    - name: exporter
      image: registry.internal/settlement-exporter:approved-build
      volumeMounts:
        - name: broker-identity
          mountPath: /var/run/broker-identity
          readOnly: true
  volumes:
    - name: broker-identity
      projected:
        sources:
          - serviceAccountToken:
              path: token
              audience: settlement-broker
              expirationSeconds: 2400

Cost and verification

Shorter token lives reduce exposure after theft but increase dependence on token refresh and issuer availability. Frequent reads of a local projected file are cheap; repeated remote token exchanges and broker authentication can add latency and rate-limit pressure. Measure refresh lead time, expiry margin, audience rejection, and how quickly the client recovers after a temporary issuer outage. The token belongs to the Pod identity, so preserving it beyond the Pod's lifetime is a design error.

Common Mistakes

  • Do not cache token bytes for the entire container lifetime.
  • Do not assume a valid signature means the token has the intended audience.
  • Do not substitute a permanent ServiceAccount token Secret for a rotating projection without accepting the added risk.

Connected lessons

Practice and check

devops
operations
Storage details