initcontainer-prestop-tcpsocket-host
Naming another host in a preStop TCP hook points init container shutdown at an off-pod address through a handler the kubelet does not support, so the hook fails and cleanup never runs.
!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
!has(ic.lifecycle) ||
!has(ic.lifecycle.preStop) ||
!has(ic.lifecycle.preStop.tcpSocket) ||
!has(ic.lifecycle.preStop.tcpSocket.host) ||
ic.lifecycle.preStop.tcpSocket.host == ""
)
spec.initContainers[*].lifecycle.preStop.tcpSocket.host must be undefined or empty ("").
Remove the host field or set it to an empty string, and prefer an exec or httpGet handler since tcpSocket hooks are unsupported. Field: spec.initContainers[*].lifecycle.preStop.tcpSocket.host.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: initcontainer-prestop-tcpsocket-host
annotations:
kubeapt.io/uuid: "31b0e769-6283-4498-938f-f8d355d53586"
security.kubeapt.io/displayName: "preStop TCP Hook Targets an Arbitrary Host"
security.kubeapt.io/description: "Naming another host in a preStop TCP hook points init container shutdown at an off-pod address through a handler the kubelet does not support, so the hook fails and cleanup never runs."
security.kubeapt.io/resource: "InitContainers"
security.kubeapt.io/severity: "Low"
security.kubeapt.io/remediation: "Remove the host field or set it to an empty string, and prefer an exec or httpGet handler since tcpSocket hooks are unsupported. Field: spec.initContainers[*].lifecycle.preStop.tcpSocket.host."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
validations:
- expression: |
!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
!has(ic.lifecycle) ||
!has(ic.lifecycle.preStop) ||
!has(ic.lifecycle.preStop.tcpSocket) ||
!has(ic.lifecycle.preStop.tcpSocket.host) ||
ic.lifecycle.preStop.tcpSocket.host == ""
)
message: |
spec.initContainers[*].lifecycle.preStop.tcpSocket.host must be undefined or empty ("").Save it as initcontainer-prestop-tcpsocket-host.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./initcontainer-prestop-tcpsocket-host.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name initcontainer-prestop-tcpsocket-host -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name initcontainer-prestop-tcpsocket-host -A