From 5ffe53160675fbf01b98e81dfc14e47790f226c2 Mon Sep 17 00:00:00 2001 From: Guangning E Date: Sun, 20 Sep 2026 08:06:59 +0800 Subject: [PATCH 1/4] fix: harden sn-operator service account token mount --- charts/sn-operator/Chart.yaml | 2 +- charts/sn-operator/templates/deployment.yaml | 3 +++ charts/sn-operator/templates/sa.yaml | 3 ++- charts/sn-operator/values.yaml | 3 +++ 4 files changed, 9 insertions(+), 2 deletions(-) diff --git a/charts/sn-operator/Chart.yaml b/charts/sn-operator/Chart.yaml index b06a492..4d3f52f 100644 --- a/charts/sn-operator/Chart.yaml +++ b/charts/sn-operator/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.20.1 +version: 0.20.2 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/charts/sn-operator/templates/deployment.yaml b/charts/sn-operator/templates/deployment.yaml index 0770695..8620359 100644 --- a/charts/sn-operator/templates/deployment.yaml +++ b/charts/sn-operator/templates/deployment.yaml @@ -26,6 +26,9 @@ spec: {{- toYaml . | nindent 8 }} {{- end }} spec: + # The operator requires Kubernetes API access. Keep this explicit because + # automatic token mounting is disabled on the service account by default. + automountServiceAccountToken: true imagePullSecrets: {{- toYaml .Values.imagePullSecrets | nindent 8 }} serviceAccountName: {{ include "sn-operator.serviceAccountName" . }} diff --git a/charts/sn-operator/templates/sa.yaml b/charts/sn-operator/templates/sa.yaml index 7267a84..c5e4927 100644 --- a/charts/sn-operator/templates/sa.yaml +++ b/charts/sn-operator/templates/sa.yaml @@ -10,4 +10,5 @@ metadata: annotations: {{- toYaml . | nindent 4 }} {{- end }} -{{- end }} \ No newline at end of file +automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }} +{{- end }} diff --git a/charts/sn-operator/values.yaml b/charts/sn-operator/values.yaml index bfc3bb6..957fd65 100644 --- a/charts/sn-operator/values.yaml +++ b/charts/sn-operator/values.yaml @@ -42,6 +42,9 @@ serviceAccount: # -- Specifies whether a service account should be created # if set to false, pre-create service account and specify the sa name, so the chart will bind the role/clusterrole to the sa. create: true + # -- Controls whether Kubernetes automatically mounts API credentials into pods using this service account. + # The operator pod explicitly enables its required token mount in the deployment template. + automountServiceAccountToken: false # Annotations to add to the service account annotations: {} # The name of the service account to use. From bfb8d0fecc6a72bcbf32270c1d107daadd220646 Mon Sep 17 00:00:00 2001 From: Guangning E Date: Sun, 20 Sep 2026 08:10:54 +0800 Subject: [PATCH 2/4] fix: preserve service account token defaults --- charts/sn-operator/Chart.yaml | 2 +- charts/sn-operator/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/sn-operator/Chart.yaml b/charts/sn-operator/Chart.yaml index 4d3f52f..b06a492 100644 --- a/charts/sn-operator/Chart.yaml +++ b/charts/sn-operator/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.20.2 +version: 0.20.1 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/charts/sn-operator/values.yaml b/charts/sn-operator/values.yaml index 957fd65..de09f48 100644 --- a/charts/sn-operator/values.yaml +++ b/charts/sn-operator/values.yaml @@ -44,7 +44,7 @@ serviceAccount: create: true # -- Controls whether Kubernetes automatically mounts API credentials into pods using this service account. # The operator pod explicitly enables its required token mount in the deployment template. - automountServiceAccountToken: false + automountServiceAccountToken: true # Annotations to add to the service account annotations: {} # The name of the service account to use. From 16016f6e5db517641b27eb11be700799b7aeb7a2 Mon Sep 17 00:00:00 2001 From: Guangning E Date: Sun, 20 Sep 2026 08:11:20 +0800 Subject: [PATCH 3/4] docs: clarify operator token requirement --- charts/sn-operator/templates/deployment.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/sn-operator/templates/deployment.yaml b/charts/sn-operator/templates/deployment.yaml index 8620359..852b0fb 100644 --- a/charts/sn-operator/templates/deployment.yaml +++ b/charts/sn-operator/templates/deployment.yaml @@ -26,8 +26,8 @@ spec: {{- toYaml . | nindent 8 }} {{- end }} spec: - # The operator requires Kubernetes API access. Keep this explicit because - # automatic token mounting is disabled on the service account by default. + # The operator requires Kubernetes API access, even when automatic token + # mounting is disabled on the service account. automountServiceAccountToken: true imagePullSecrets: {{- toYaml .Values.imagePullSecrets | nindent 8 }} From 791b56c999f7137624c4a22b0d0747e99cecbfbf Mon Sep 17 00:00:00 2001 From: Guangning E Date: Sun, 20 Sep 2026 08:13:33 +0800 Subject: [PATCH 4/4] docs: add manual service account token example --- charts/sn-operator/templates/deployment.yaml | 3 -- charts/sn-operator/values.yaml | 32 +++++++++++++++++++- 2 files changed, 31 insertions(+), 4 deletions(-) diff --git a/charts/sn-operator/templates/deployment.yaml b/charts/sn-operator/templates/deployment.yaml index 852b0fb..0770695 100644 --- a/charts/sn-operator/templates/deployment.yaml +++ b/charts/sn-operator/templates/deployment.yaml @@ -26,9 +26,6 @@ spec: {{- toYaml . | nindent 8 }} {{- end }} spec: - # The operator requires Kubernetes API access, even when automatic token - # mounting is disabled on the service account. - automountServiceAccountToken: true imagePullSecrets: {{- toYaml .Values.imagePullSecrets | nindent 8 }} serviceAccountName: {{ include "sn-operator.serviceAccountName" . }} diff --git a/charts/sn-operator/values.yaml b/charts/sn-operator/values.yaml index de09f48..a5d1d72 100644 --- a/charts/sn-operator/values.yaml +++ b/charts/sn-operator/values.yaml @@ -43,7 +43,8 @@ serviceAccount: # if set to false, pre-create service account and specify the sa name, so the chart will bind the role/clusterrole to the sa. create: true # -- Controls whether Kubernetes automatically mounts API credentials into pods using this service account. - # The operator pod explicitly enables its required token mount in the deployment template. + # The operator requires Kubernetes API credentials. When set to false, configure + # volumeMounts and volumes below to project the service account credentials manually. automountServiceAccountToken: true # Annotations to add to the service account annotations: {} @@ -73,6 +74,35 @@ securityContext: {} # runAsNonRoot: true # runAsUser: 1000 +# -- Additional volume mounts for the operator container. +# When serviceAccount.automountServiceAccountToken is false, the following example +# mounts the credentials required by the operator at the standard in-cluster path. +volumeMounts: [] + # - name: kube-api-access + # mountPath: /var/run/secrets/kubernetes.io/serviceaccount + # readOnly: true + +# -- Additional volumes for the operator pod. +volumes: [] + # - name: kube-api-access + # projected: + # defaultMode: 420 + # sources: + # - serviceAccountToken: + # expirationSeconds: 3607 + # path: token + # - configMap: + # name: kube-root-ca.crt + # items: + # - key: ca.crt + # path: ca.crt + # - downwardAPI: + # items: + # - path: namespace + # fieldRef: + # apiVersion: v1 + # fieldPath: metadata.namespace + # -- Add resource limits and requests resources: {} # We usually recommend not to specify default resources and to leave this as a conscious