From b6c6ff6a7e84f4843d0a340ab1ad571d335d1a08 Mon Sep 17 00:00:00 2001 From: Katarina Strenkova Date: Mon, 21 Sep 2026 16:01:05 +0200 Subject: [PATCH] Disable service account token mounting in test pods Set AutomountServiceAccountToken to false unconditionally in test pod spec. Test pods that need cluster access authenticate with a kubeconfig mounted via spec.kubeconfigSecretName, not the service account token. No test framework uses in-cluster credentials. This change reduces attack surface and follows Jobs-to-Pods migration (ee982d7) that eliminated ServiceAccount usage. --- .../test.openstack.org_ansibletests.yaml | 9 +++-- .../test.openstack.org_horizontests.yaml | 9 +++-- api/bases/test.openstack.org_tempests.yaml | 9 +++-- api/bases/test.openstack.org_tobikoes.yaml | 9 +++-- api/v1beta1/common.go | 9 +++-- api/v1beta1/common_webhook.go | 4 +-- .../test.openstack.org_ansibletests.yaml | 9 +++-- .../test.openstack.org_horizontests.yaml | 9 +++-- .../bases/test.openstack.org_tempests.yaml | 9 +++-- .../bases/test.openstack.org_tobikoes.yaml | 9 +++-- .../test-operator.clusterserviceversion.yaml | 36 +++++++++---------- go.mod | 2 +- internal/util/common.go | 3 +- 13 files changed, 57 insertions(+), 69 deletions(-) diff --git a/api/bases/test.openstack.org_ansibletests.yaml b/api/bases/test.openstack.org_ansibletests.yaml index bfedd1c7..74e0c12e 100644 --- a/api/bases/test.openstack.org_ansibletests.yaml +++ b/api/bases/test.openstack.org_ansibletests.yaml @@ -884,11 +884,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean resources: default: diff --git a/api/bases/test.openstack.org_horizontests.yaml b/api/bases/test.openstack.org_horizontests.yaml index 9dbca724..ea23e7cd 100644 --- a/api/bases/test.openstack.org_horizontests.yaml +++ b/api/bases/test.openstack.org_horizontests.yaml @@ -891,11 +891,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean projectNameXpath: description: |- diff --git a/api/bases/test.openstack.org_tempests.yaml b/api/bases/test.openstack.org_tempests.yaml index 394fd0d0..1b08f480 100644 --- a/api/bases/test.openstack.org_tempests.yaml +++ b/api/bases/test.openstack.org_tempests.yaml @@ -883,11 +883,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean rerunFailedTests: default: false diff --git a/api/bases/test.openstack.org_tobikoes.yaml b/api/bases/test.openstack.org_tobikoes.yaml index e7ce768e..ba60c65c 100644 --- a/api/bases/test.openstack.org_tobikoes.yaml +++ b/api/bases/test.openstack.org_tobikoes.yaml @@ -898,11 +898,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean publicKey: default: "" diff --git a/api/v1beta1/common.go b/api/v1beta1/common.go index 154b2043..26a07c37 100644 --- a/api/v1beta1/common.go +++ b/api/v1beta1/common.go @@ -50,11 +50,10 @@ type CommonOptions struct { // +optional // Use with caution! This parameter specifies whether test-operator should spawn // test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - // runAsNonRoot: false, automountServiceAccountToken: true, and the default - // capabilities on top of capabilities that are usually needed by the test - // pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - // needed for certain test-operator functionalities to work properly (e.g.: - // extraRPMs in Tempest CR, or a certain set of tobiko tests). + // runAsNonRoot: false, and the default capabilities on top of capabilities that + // are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + // deemed insecure but it is needed for certain test-operator functionalities to + // work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). Privileged bool `json:"privileged"` // +operator-sdk:csv:customresourcedefinitions:type=spec diff --git a/api/v1beta1/common_webhook.go b/api/v1beta1/common_webhook.go index 91c25ba1..49d5fd6a 100644 --- a/api/v1beta1/common_webhook.go +++ b/api/v1beta1/common_webhook.go @@ -62,8 +62,8 @@ const ( // WarnPrivilegedModeOn WarnPrivilegedModeOn = "%s.Spec.Privileged is set to true. This means that test pods " + "are spawned with allowPrivilegedEscalation: true, readOnlyRootFilesystem: false, " + - "runAsNonRoot: false, automountServiceAccountToken: true and default " + - "capabilities on top of those required by the test operator (NET_ADMIN, NET_RAW)." + "runAsNonRoot: false and default capabilities on top of those required by the " + + "test operator (NET_ADMIN, NET_RAW)." // WarnPrivilegedModeOff WarnPrivilegedModeOff = "%[1]s.Spec.Privileged is set to false. Note, that a certain " + diff --git a/config/crd/bases/test.openstack.org_ansibletests.yaml b/config/crd/bases/test.openstack.org_ansibletests.yaml index bfedd1c7..74e0c12e 100644 --- a/config/crd/bases/test.openstack.org_ansibletests.yaml +++ b/config/crd/bases/test.openstack.org_ansibletests.yaml @@ -884,11 +884,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean resources: default: diff --git a/config/crd/bases/test.openstack.org_horizontests.yaml b/config/crd/bases/test.openstack.org_horizontests.yaml index 9dbca724..ea23e7cd 100644 --- a/config/crd/bases/test.openstack.org_horizontests.yaml +++ b/config/crd/bases/test.openstack.org_horizontests.yaml @@ -891,11 +891,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean projectNameXpath: description: |- diff --git a/config/crd/bases/test.openstack.org_tempests.yaml b/config/crd/bases/test.openstack.org_tempests.yaml index 394fd0d0..1b08f480 100644 --- a/config/crd/bases/test.openstack.org_tempests.yaml +++ b/config/crd/bases/test.openstack.org_tempests.yaml @@ -883,11 +883,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean rerunFailedTests: default: false diff --git a/config/crd/bases/test.openstack.org_tobikoes.yaml b/config/crd/bases/test.openstack.org_tobikoes.yaml index e7ce768e..ba60c65c 100644 --- a/config/crd/bases/test.openstack.org_tobikoes.yaml +++ b/config/crd/bases/test.openstack.org_tobikoes.yaml @@ -898,11 +898,10 @@ spec: description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). type: boolean publicKey: default: "" diff --git a/config/manifests/bases/test-operator.clusterserviceversion.yaml b/config/manifests/bases/test-operator.clusterserviceversion.yaml index e1e4b260..1323a3a8 100644 --- a/config/manifests/bases/test-operator.clusterserviceversion.yaml +++ b/config/manifests/bases/test-operator.clusterserviceversion.yaml @@ -111,11 +111,10 @@ spec: - description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). displayName: Privileged path: privileged - description: StorageClass used to create any test-operator related PVCs. @@ -340,11 +339,10 @@ spec: - description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). displayName: Privileged path: privileged - description: |- @@ -464,11 +462,10 @@ spec: - description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). displayName: Privileged path: privileged - description: |- @@ -1118,11 +1115,10 @@ spec: - description: |- Use with caution! This parameter specifies whether test-operator should spawn test pods with allowedPrivilegedEscalation: true, readOnlyRootFilesystem: false, - runAsNonRoot: false, automountServiceAccountToken: true, and the default - capabilities on top of capabilities that are usually needed by the test - pods (NET_ADMIN, NET_RAW). This parameter is deemed insecure but it is - needed for certain test-operator functionalities to work properly (e.g.: - extraRPMs in Tempest CR, or a certain set of tobiko tests). + runAsNonRoot: false, and the default capabilities on top of capabilities that + are usually needed by the test pods (NET_ADMIN, NET_RAW). This parameter is + deemed insecure but it is needed for certain test-operator functionalities to + work properly (e.g.: extraRPMs in Tempest CR, or a certain set of tobiko tests). displayName: Privileged path: privileged - description: Public Key diff --git a/go.mod b/go.mod index 4f7a75ca..f9f13ef7 100644 --- a/go.mod +++ b/go.mod @@ -101,7 +101,7 @@ require ( k8s.io/component-base v0.33.13 // indirect k8s.io/klog/v2 v2.130.1 // indirect k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff // indirect - k8s.io/utils v0.0.0-20250820121507-0af2bda4dd1d // indirect + k8s.io/utils v0.0.0-20250820121507-0af2bda4dd1d sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.31.2 // indirect sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect sigs.k8s.io/structured-merge-diff/v4 v4.6.0 // indirect diff --git a/internal/util/common.go b/internal/util/common.go index 166b0ff9..0d590ae9 100644 --- a/internal/util/common.go +++ b/internal/util/common.go @@ -6,6 +6,7 @@ import ( "github.com/openstack-k8s-operators/lib-common/modules/storage" corev1 "k8s.io/api/core/v1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/utils/ptr" ) const ( @@ -99,7 +100,7 @@ func BuildTestPod( Annotations: annotations, }, Spec: corev1.PodSpec{ - AutomountServiceAccountToken: &privileged, + AutomountServiceAccountToken: ptr.To(false), RestartPolicy: corev1.RestartPolicyNever, Tolerations: tolerations, NodeSelector: nodeSelector,