External ServiceAccount token signer

외부 서비스 계정 토큰 서명기

Move ServiceAccount token signing to a key system outside the API server.

···
html
<div class="stage" data-phase="0"><div class="title">TOKEN SIGNING BOUNDARY</div><div class="signflow"><div class="panel api">API SERVER<small>token request</small></div><div class="wire"><span>→</span><span>←</span></div><div class="panel signer">EXTERNAL SIGNER<small>private key</small></div></div><div class="panel verify">PUBLIC KEY · verify pending</div></div>
css
.stage{width:min(94vw,760px);height:min(88vh,330px);padding:clamp(9px,2.6vmin,20px);border:1px solid var(--line);border-radius:14px;background:var(--surface);font:600 clamp(12px,2.5vmin,16px)/1.3 "Pretendard Variable",Pretendard,-apple-system,BlinkMacSystemFont,"Apple SD Gothic Neo",sans-serif;display:flex;flex-direction:column;gap:clamp(6px,1.7vmin,12px);overflow:hidden;position:relative}.stage *{min-width:0}.stage .title{color:var(--accent);font-weight:800}.stage .sub{color:var(--muted)}.stage .row{display:flex;align-items:center;gap:clamp(5px,1.6vmin,12px)}.stage .panel{border:1px solid var(--line);border-radius:8px;background:var(--bg);padding:clamp(6px,1.6vmin,12px)}.stage .mono{font-family:ui-monospace,SFMono-Regular,monospace;font-size:clamp(12px,2.5vmin,15px)}.stage .grow{flex:1}.stage .on{color:var(--accent)}.signflow{flex:1;display:flex;align-items:center;justify-content:space-between;gap:5px}.signflow .panel{width:42%;text-align:center}.signflow small{display:block;margin-top:6px;color:var(--muted);font-size:clamp(12px,2.5vmin,14px)}.wire{display:flex;flex-direction:column;color:var(--line);font-size:clamp(17px,4vmin,26px)}.verify{text-align:center;color:var(--muted)}.stage[data-phase="1"] .wire span:first-child,.stage[data-phase="1"] .signer{color:var(--accent);border-color:var(--accent)}.stage[data-phase="2"] .wire span:last-child,.stage[data-phase="2"] .verify{color:var(--accent);border-color:var(--accent);background:color-mix(in srgb,var(--accent) 12%,var(--surface))}.stage[data-phase="2"] .verify{font-size:0}.stage[data-phase="2"] .verify:after{content:'PUBLIC KEY · signature valid';font-size:clamp(12px,2.5vmin,16px)}
js
const stage=document.querySelector('.stage');let phase=0;function advance(){phase=(phase+1)%3;stage.dataset.phase=String(phase)}const timer=setInterval(advance,1200);stage.addEventListener('pointerdown',()=>{clearInterval(timer);advance()})

An external signer lets the API server request a ServiceAccount token while another system holds the signing key. The API server discovers public keys from that signer to validate issued tokens.

The demo moves a token request to the signer and then verifies the result. This option is stable in Kubernetes 1.36; signer availability and key rotation still require an operations plan.

When to use

Use it when ServiceAccount signing keys must live in centralized key management.

Open as page ↗