Q: In a shared multi-tenant Kubernetes cluster, Flux v2 by default uses its own cluster-admin privileges to reconcile manifests from tenant Git repositories. A malicious or compromised tenant team commits a ClusterRoleBinding granting themselves cluster-admin. How do you design and enforce strict multi-tenant isolation in Flux v2 using ServiceAccount impersonation?
Production runbook for hardening multi-tenant Flux v2 deployments using Kustomization serviceAccountName impersonation, rootless controllers, and Kyverno admission policy validation.
Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Configure Flux Kustomization with Explicit ServiceAccount Impersonation
Force the Flux reconciliation engine to assume the tenant's restricted identity:
- Tenant Kustomization Spec: Configured
spec.serviceAccountName: tenant-a-reconcilerin the tenant'sKustomizationCRD. - Scoping Execution: When applying manifests, the Flux kustomize-controller impersonates
tenant-a-reconciler, ensuring operations are constrained strictly by that ServiceAccount's namespace-scoped RBAC Role.
Define Least-Privilege Tenant RBAC Role & RoleBinding
Restrict tenant reconciliation permissions strictly to their allocated namespace:
- Namespace Role: Created a
Rolein namespacetenant-apermitting management of Deployments, Services, ConfigMaps, and Secrets. - Deny Cluster-Scoped Resources: Prohibited creation of ClusterRoles, MutatingWebhookConfigurations, and PersistentVolumes.
Enforce ServiceAccount Assignment via Kyverno Admission Policy
Prevent tenants from creating Flux Kustomizations without ServiceAccount bindings:
- Kyverno ClusterPolicy: Enforced rule: Any
KustomizationorHelmReleaseCRD created in a tenant namespace MUST explicitly declare a validspec.serviceAccountName. - Automated Rejection: If a tenant omits
serviceAccountName(attempting to trigger default cluster-admin execution), Kyverno blocks the commit admission.
Isolate Git Repositories with Deploy Keys & GPG Commit Verification
Ensure repository source authenticity and encrypted transport:
- GitRepository CRD: Scoped GitRepository credentials using read-only SSH deploy keys stored in tenant namespaces.
- GPG Signature Verification: Enabled
verify: { mode: 'head', secretRef: { name: 'tenant-gpg-keys' } }to reject unsigned or tampered Git commits.
- Enforce spec.serviceAccountName impersonation on all Flux Kustomization CRDs.
- Confine tenant ServiceAccount permissions strictly to their allocated namespace via RBAC.
- Use Kyverno admission policies to reject any Flux manifest lacking an explicit ServiceAccount.
- Mandate GPG commit signature verification to reject untrusted or unsigned Git commits.