DEV Community

Discussion on: Kubernetes: Certificates, Tokens, Authentication and Service Accounts

Collapse
 
danielkun profile image
Daniel Albuschat

Thanks!
I have been told by multiple sources, however, that using Service Account tokens isn't a silver bullet and not recommended, either O_o

The reason is that the tokens are "ephemeral", whatever that means. I have yet to find out when/why they will be recreated. I personally don't see the disadvantage to certs, though, since you should totally periodically roll your credentials anyways, so I'd suggest to do this with certs, too. But it turns out, as described in the article, that rolling (and therefore invalidating the old) certs is a huge PITA.

It's all still a mystery to me.