ciliumclusterwidenetworkpolicy-egress-world
The world entity covers every address outside the cluster, so a cluster-wide rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source.
!has(object.spec) || (
!object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
!object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
)
CiliumClusterwideNetworkPolicies must not allow ingress from or egress to the 'world' entity.
Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: ciliumclusterwidenetworkpolicy-egress-world
annotations:
kubeapt.io/uuid: "0c5ae649-347c-41d8-b00e-f606594917f8"
security.kubeapt.io/displayName: "Permits Traffic to the world Entity"
security.kubeapt.io/description: "The world entity covers every address outside the cluster, so a cluster-wide rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source."
security.kubeapt.io/resource: "CiliumClusterwideNetworkPolicies"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities."
security.kubeapt.io/product: "Cilium"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- cilium.io
apiVersions:
- v2
operations:
- CREATE
- UPDATE
resources:
- ciliumclusterwidenetworkpolicies
validations:
- expression: |
!has(object.spec) || (
!object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
!object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
)
message: |
CiliumClusterwideNetworkPolicies must not allow ingress from or egress to the 'world' entity.Save it as ciliumclusterwidenetworkpolicy-egress-world.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./ciliumclusterwidenetworkpolicy-egress-world.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name ciliumclusterwidenetworkpolicy-egress-world -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name ciliumclusterwidenetworkpolicy-egress-world -A