role-wildcard-rules
A wildcard in apiGroups, resources or verbs hands over an entire API group, every resource type or every operation on them within the namespace, and silently widens to each CRD installed later.
!has(object.rules) ||
object.rules.all(r,
!((has(r.apiGroups) && r.apiGroups.exists(ag, ag == "*")) ||
(has(r.resources) && r.resources.exists(res, res == "*")) ||
(has(r.verbs) && r.verbs.exists(v, v == "*")))
)
Wildcard rules (apiGroups/resources/verbs all "*") are disallowed.
Replace each wildcard entry with the explicit API groups, resources and verbs the workload actually calls. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: role-wildcard-rules
annotations:
kubeapt.io/uuid: "104d53d3-4e2d-4c44-b14a-4a95b7dba910"
security.kubeapt.io/displayName: "Uses Wildcard apiGroups, Resources or Verbs"
security.kubeapt.io/description: "A wildcard in apiGroups, resources or verbs hands over an entire API group, every resource type or every operation on them within the namespace, and silently widens to each CRD installed later."
security.kubeapt.io/resource: "Roles"
security.kubeapt.io/severity: "Critical"
security.kubeapt.io/remediation: "Replace each wildcard entry with the explicit API groups, resources and verbs the workload actually calls. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- rbac.authorization.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- roles
validations:
- expression: |
!has(object.rules) ||
object.rules.all(r,
!((has(r.apiGroups) && r.apiGroups.exists(ag, ag == "*")) ||
(has(r.resources) && r.resources.exists(res, res == "*")) ||
(has(r.verbs) && r.verbs.exists(v, v == "*")))
)
message: |
Wildcard rules (apiGroups/resources/verbs all "*") are disallowed.Save it as role-wildcard-rules.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./role-wildcard-rules.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name role-wildcard-rules -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name role-wildcard-rules -A