Skip to content

Lab 05 — Kubernetes Identity Audit

Item Details
Lab ID K8S-IAM-LAB-05
Difficulty Advanced
Estimated Time 3–4 Hours
Environment Kubernetes Cluster (Amazon EKS / Azure AKS / Google GKE / kind)
Platform Kubernetes
Cost Free (kind) / Cloud Charges Apply
Primary Role Kubernetes Security Engineer
Module Module 02 — Kubernetes Identity & Access Management
Previous Lab Lab 04 — Secure Kubernetes Authentication with OIDC & IAM Roles for Service Accounts (IRSA)

CloudNova Technologies has completed the migration of hundreds of applications to Kubernetes.

The Kubernetes platform has evolved over several years, and multiple engineering teams have independently created:

  • Service Accounts
  • Roles
  • ClusterRoles
  • RoleBindings
  • ClusterRoleBindings
  • IAM Roles
  • OIDC Integrations

During an internal audit, several concerns were raised:

  • Excessive cluster-admin assignments
  • Shared Service Accounts
  • Unused Roles
  • Wildcard permissions
  • Default Service Accounts in production
  • Missing namespace isolation
  • Stale RBAC objects
  • Missing workload identity governance

The Chief Information Security Officer (CISO) has requested a full Kubernetes Identity Audit before the next compliance review.

As the Kubernetes Security Engineer, you must assess the environment, identify security risks, document findings, and recommend improvements.


By completing this lab, you will learn how to:

  • Audit Kubernetes identities
  • Review Service Accounts
  • Assess RBAC implementation
  • Review ClusterRoles
  • Audit RoleBindings
  • Audit ClusterRoleBindings
  • Review workload authentication
  • Assess IRSA implementation
  • Detect excessive permissions
  • Identify orphaned identities
  • Evaluate least privilege
  • Produce an enterprise identity audit report

CloudNova Kubernetes Platform
Kubernetes API Server
Authentication & OIDC
Authorization (RBAC)
┌───────────────┬───────────────┬───────────────┐
│ │ │
Service Accounts Human Users Cloud Identities
│ │ │
└───────────────┼───────────────┘
Kubernetes Resources
Identity Audit Review

By the end of this lab you will have:

  • Audited all Service Accounts
  • Reviewed RBAC implementation
  • Identified privileged identities
  • Reviewed authentication mechanisms
  • Audited workload identities
  • Assessed least privilege
  • Reviewed cloud identity integration
  • Produced an enterprise identity audit report

Before starting:

  • Complete Module 01
  • Complete Module 02 Labs 01–04
  • Kubernetes cluster running
  • kubectl installed
  • AWS CLI (for IRSA validation, if applicable)

Tool Purpose
kubectl Kubernetes administration
Docker Desktop Local cluster runtime
kind Local Kubernetes
AWS CLI IRSA validation
Visual Studio Code YAML review
PowerShell / Git Bash Command execution

Perform a complete identity assessment covering:

  • Service Accounts
  • Authentication
  • RBAC
  • Roles
  • ClusterRoles
  • Bindings
  • Workload Identity
  • OIDC
  • IRSA
  • Least Privilege
  • Governance

Verify cluster connectivity.

Terminal window
kubectl cluster-info
kubectl get nodes

Confirm:

  • Cluster accessible
  • Nodes Ready

Task 02 — Inventory All Service Accounts

Section titled “Task 02 — Inventory All Service Accounts”

List every Service Account.

Terminal window
kubectl get serviceaccounts -A

Review:

  • Namespace
  • Age
  • Naming convention

Document:

  • Total Service Accounts
  • Default Service Accounts
  • Application Service Accounts
  • Administrative Service Accounts

Task 03 — Review Default Service Accounts

Section titled “Task 03 — Review Default Service Accounts”

Inspect every default Service Account.

Terminal window
kubectl describe sa default -n <namespace>

Review:

  • Token mounting
  • Usage
  • Workloads attached

Questions:

  • Is the default Service Account used by production workloads?
  • Should dedicated Service Accounts replace it?

Review authentication tokens.

Terminal window
kubectl get secrets -A

Review projected tokens.

Inspect Pods.

Terminal window
kubectl describe pod <pod-name>

Confirm:

  • Projected tokens
  • Legacy tokens
  • Token mounting

Inventory Roles.

Terminal window
kubectl get roles -A

Inspect each Role.

Terminal window
kubectl describe role <role> -n <namespace>

Review:

  • Resources
  • Verbs
  • API Groups

Identify:

  • Wildcard permissions
  • Excessive privileges
  • Duplicate Roles

List ClusterRoles.

Terminal window
kubectl get clusterroles

Review:

Terminal window
kubectl describe clusterrole <role-name>

Identify:

  • cluster-admin
  • admin
  • edit
  • view
  • Custom ClusterRoles

Assess:

  • Business justification
  • Least privilege
  • Administrative scope

Review:

Terminal window
kubectl get rolebindings -A

Inspect bindings.

Confirm:

  • Correct namespace
  • Correct Service Account
  • Correct Role

Look for:

  • Obsolete bindings
  • Duplicate bindings
  • Incorrect namespace assignments

Review:

Terminal window
kubectl get clusterrolebindings

Inspect each binding.

Questions:

  • Who has cluster-admin?
  • Why do they need it?
  • Is approval documented?

Test permissions.

Examples:

Terminal window
kubectl auth can-i get pods
kubectl auth can-i create deployments
kubectl auth can-i delete namespaces
kubectl auth can-i get secrets

Document:

Allowed

Denied

Unexpected permissions


Inspect Pods.

Terminal window
kubectl get pods -A

Review:

Terminal window
kubectl describe pod <pod-name>

Confirm:

  • Dedicated Service Account
  • Default Service Account
  • Token mounted
  • automountServiceAccountToken configuration

Task 11 — Audit OIDC & IRSA (Amazon EKS)

Section titled “Task 11 — Audit OIDC & IRSA (Amazon EKS)”

If using Amazon EKS:

Review:

Terminal window
aws eks describe-cluster \
--name <cluster-name>

Verify:

  • OIDC Provider
  • IAM Roles
  • IAM Policies
  • Trust Relationships

Confirm:

  • One IAM Role per workload
  • Least privilege
  • No shared IAM roles

Task 12 — Review Authentication Governance

Section titled “Task 12 — Review Authentication Governance”

Evaluate:

  • Naming standards
  • Namespace ownership
  • Service Account lifecycle
  • Identity documentation
  • Credential rotation
  • Approval process

Look for:

  • Shared Service Accounts
  • Default Service Accounts in production
  • Wildcard (*) permissions
  • cluster-admin misuse
  • Long-lived credentials
  • Orphaned Roles
  • Unused Service Accounts
  • Excessive ClusterRoleBindings

Assign severity:

  • Critical
  • High
  • Medium
  • Low

Task 14 — Identity Compliance Assessment

Section titled “Task 14 — Identity Compliance Assessment”

Evaluate compliance against:

  • CIS Kubernetes Benchmark
  • Kubernetes Security Best Practices
  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • Principle of Least Privilege

Task 15 — Create an Identity Risk Register

Section titled “Task 15 — Create an Identity Risk Register”
Finding Risk Severity Recommendation

Examples:

  • Shared Service Accounts
  • Default identities
  • Excessive RBAC
  • Missing IRSA
  • Missing OIDC
  • Excessive ClusterRoles

Task 16 — Enterprise Identity Maturity Assessment

Section titled “Task 16 — Enterprise Identity Maturity Assessment”

Evaluate each domain.

Domain Rating (1–5)
Authentication
RBAC
Least Privilege
Service Accounts
IRSA / Workload Identity
Governance
Documentation
Compliance

Task 17 — Produce an Enterprise Audit Report

Section titled “Task 17 — Produce an Enterprise Audit Report”

Document:

Environment:
Cluster:
Assessment Date:
Auditor:
Authentication Review
Service Account Review
RBAC Review
Role Review
ClusterRole Review
RoleBinding Review
OIDC Review
IRSA Review
Least Privilege Assessment
Compliance Status
Critical Findings
High Findings
Medium Findings
Low Findings
Recommendations
Overall Identity Security Rating

Prioritise improvements.

Priority 1

  • Remove unnecessary cluster-admin
  • Replace default Service Accounts
  • Remove wildcard permissions

Priority 2

  • Implement IRSA
  • Review trust relationships
  • Rotate credentials

Priority 3

  • Standardise naming
  • Improve documentation
  • Quarterly identity audits

Capture evidence for:

  • Service Accounts
  • Roles
  • ClusterRoles
  • RoleBindings
  • ClusterRoleBindings
  • Permission testing
  • IRSA configuration
  • OIDC provider
  • Identity maturity assessment
  • Final audit report

Remove any temporary audit resources created during the assessment.

Verify:

  • No unnecessary Service Accounts
  • No test Roles
  • No temporary RoleBindings

By completing this lab, you will be able to:

  • Perform Kubernetes identity audits
  • Review enterprise RBAC
  • Assess workload authentication
  • Evaluate Service Accounts
  • Audit IAM integrations
  • Review OIDC configuration
  • Assess least privilege
  • Identify privilege escalation risks
  • Produce compliance evidence
  • Conduct enterprise security reviews

Which Kubernetes object provides an identity for workloads?

  • A. ConfigMap
  • B. Service Account
  • C. Deployment
  • D. Secret

Answer: B


Which RBAC object grants permissions across the entire cluster?

  • A. Role
  • B. Service
  • C. ClusterRole
  • D. ReplicaSet

Answer: C


Why should wildcard (*) permissions generally be avoided?

  • A. They reduce cluster performance.
  • B. They violate the principle of least privilege by granting broad access.
  • C. They prevent Pods from starting.
  • D. They disable Kubernetes authentication.

Answer: B


What is the primary benefit of IAM Roles for Service Accounts (IRSA) on Amazon EKS?

  • A. It increases Pod scheduling speed.
  • B. It replaces RBAC completely.
  • C. It provides temporary AWS credentials without storing long-lived access keys.
  • D. It automatically encrypts Kubernetes Secrets.

Answer: C


Which finding should normally be considered the highest priority during an identity audit?

  • A. Missing labels on Namespaces
  • B. An unused ConfigMap
  • C. Broad use of the cluster-admin role without business justification
  • D. An old ReplicaSet

Answer: C


In this lab, you performed a comprehensive enterprise identity audit of a Kubernetes environment by reviewing Service Accounts, RBAC objects, authentication mechanisms, workload identities, and cloud identity integrations. You assessed compliance with the principle of least privilege, identified excessive permissions and governance gaps, and prioritised remediation activities based on business risk.

These auditing techniques mirror the identity governance and access reviews carried out by Kubernetes Platform Engineering, Cloud Security, and Governance, Risk & Compliance (GRC) teams before production deployments, security assessments, and regulatory audits.


➡️ Runbook 01 — Kubernetes Identity & Access Health Assessment

In the next exercise, you will move from implementation to day-to-day operations by performing routine health checks on Kubernetes authentication, Service Accounts, RBAC, workload identities, and access controls to ensure the platform remains secure and compliant over time.