HIGH
Source
Kube Hunter
ID
KHV005

Access to Kubernetes API

Kubernetes API was accessed with Pod Service Account or without Authentication (see report message for details).

Secure access to your Kubernetes API.

It is recommended to explicitly specify a Service Account for all of your workloads (serviceAccountName in Pod.Spec), and manage their permissions according to the least privilege principal.

Consider opting out automatic mounting of SA token using automountServiceAccountToken: false on ServiceAccount resource or Pod.spec.