← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Grants the impersonate Verb

role-rbac-impersonate

severityCritical resourceRoles productKubernetes bundles1

Impersonation lets the holder send requests as any other user, group or service account, borrowing the permissions of far more privileged identities without ever being granted those permissions in its own bindings.

Rejects unless

!has(object.rules) || object.rules.all(r,
  !(has(r.verbs) && has(r.resources) &&
    r.verbs.exists(v, v == "impersonate" || v == "*") &&
    r.resources.exists(res, variables.impersonateResources.exists(ir, ir == res))
  )
)

Roles must not grant the impersonate verb on users, groups or serviceaccounts.

Variables

impersonateResources

["users","groups","serviceaccounts","uids","userextras","*"]

Remediation

Remove the impersonate verb, and any wildcard verb, from every rule covering users, groups, serviceaccounts, uids or userextras. Fields: rules[*].resources, rules[*].verbs.

Applies to

  • roles · rbac.authorization.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: role-rbac-impersonate
  annotations:
    kubeapt.io/uuid: "1cf87d15-93d3-4aaa-8540-c86b819b3e67"
    security.kubeapt.io/displayName: "Grants the impersonate Verb"
    security.kubeapt.io/description: "Impersonation lets the holder send requests as any other user, group or service account, borrowing the permissions of far more privileged identities without ever being granted those permissions in its own bindings."
    security.kubeapt.io/resource: "Roles"
    security.kubeapt.io/severity: "Critical"
    security.kubeapt.io/remediation: "Remove the impersonate verb, and any wildcard verb, from every rule covering users, groups, serviceaccounts, uids or userextras. Fields: rules[*].resources, rules[*].verbs."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - rbac.authorization.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - roles
  variables:
  - name: impersonateResources
    expression: |
      ["users","groups","serviceaccounts","uids","userextras","*"]
  validations:
  - expression: |
      !has(object.rules) || object.rules.all(r,
        !(has(r.verbs) && has(r.resources) &&
          r.verbs.exists(v, v == "impersonate" || v == "*") &&
          r.resources.exists(res, variables.impersonateResources.exists(ir, ir == res))
        )
      )
    message: |
      Roles must not grant the impersonate verb on users, groups or serviceaccounts.

Save it as role-rbac-impersonate.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./role-rbac-impersonate.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name role-rbac-impersonate -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name role-rbac-impersonate -A