Set Expiry of Kubernetes service tokens

Viewed 6715
2 Answers

Currently the default service account JWT tokens in Kubernetes are considered as “forever” tokens. They don’t expire and are valid for as long as the service account exists. I fear that your goal might nor be possible to achieve from the Kubernetes side.

I am posting this answer as a community wiki. Feel free to expand it if you know how to approach it from another side.

I hope this helps.

From the docs here you can use expirationSeconds to set expiry time of the JWT token. This property is not configurable on the default service account token.

apiVersion: v1
kind: Pod
metadata:
  name: nginx
spec:
  containers:
  - image: nginx
    name: nginx
    volumeMounts:
    - mountPath: /var/run/secrets/tokens
      name: vault-token
  serviceAccountName: build-robot
  volumes:
  - name: vault-token
    projected:
      sources:
      - serviceAccountToken:
          path: vault-token
          expirationSeconds: 7200
          audience: vault
Related