← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Binds a Privileged Role Such as cluster-admin

clusterrolebinding-powerful-roles

severityHigh resourceClusterRoleBindings productKubernetes bundles1

Roles like cluster-admin, admin and edit carry sweeping verbs across nearly every API resource, so one compromised subject in the binding gains full control of the cluster and every secret in it.

Rejects unless

!has(object.roleRef) || !(object.roleRef.kind in ["ClusterRole","Role"] &&
  variables.powerfulRoles.exists(rn, rn == object.roleRef.name))

ClusterRoleBindings must not reference powerful roles such as cluster-admin/admin/edit.

Variables

powerfulRoles

["cluster-admin","admin","edit","ns-admin","full-access"]

Remediation

Point roleRef at a purpose-built role that lists only the resources and verbs the subject needs. Fields: roleRef.kind, roleRef.name.

Applies to

  • clusterrolebindings · rbac.authorization.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: clusterrolebinding-powerful-roles
  annotations:
    kubeapt.io/uuid: "0a1888ef-7dbe-4285-a112-610213251fb6"
    security.kubeapt.io/displayName: "Binds a Privileged Role Such as cluster-admin"
    security.kubeapt.io/description: "Roles like cluster-admin, admin and edit carry sweeping verbs across nearly every API resource, so one compromised subject in the binding gains full control of the cluster and every secret in it."
    security.kubeapt.io/resource: "ClusterRoleBindings"
    security.kubeapt.io/severity: "High"
    security.kubeapt.io/remediation: "Point roleRef at a purpose-built role that lists only the resources and verbs the subject needs. Fields: roleRef.kind, roleRef.name."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - rbac.authorization.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - clusterrolebindings
  variables:
  - name: powerfulRoles
    expression: |
      ["cluster-admin","admin","edit","ns-admin","full-access"]
  validations:
  - expression: |
      !has(object.roleRef) || !(object.roleRef.kind in ["ClusterRole","Role"] &&
        variables.powerfulRoles.exists(rn, rn == object.roleRef.name))
    message: |
      ClusterRoleBindings must not reference powerful roles such as cluster-admin/admin/edit.

Save it as clusterrolebinding-powerful-roles.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./clusterrolebinding-powerful-roles.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name clusterrolebinding-powerful-roles -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name clusterrolebinding-powerful-roles -A