← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Is Mutable at Runtime

configmap-immutability

severityLow resourceConfigMaps productKubernetes bundles1

A mutable ConfigMap can be rewritten by anyone with update access, silently changing application configuration, feature flags or trusted endpoints inside running pods with no new image and no deployment.

Rejects unless

has(object.immutable) && object.immutable == true

immutable must be set to true to prevent runtime tampering.

Remediation

Set immutable to true on the ConfigMap and ship changes by creating a new versioned ConfigMap that the workload is repointed to. Field: immutable.

Applies to

  • configmaps · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: configmap-immutability
  annotations:
    kubeapt.io/uuid: "347134fc-2e95-4b42-93bc-d9098b018a6b"
    security.kubeapt.io/displayName: "Is Mutable at Runtime"
    security.kubeapt.io/description: "A mutable ConfigMap can be rewritten by anyone with update access, silently changing application configuration, feature flags or trusted endpoints inside running pods with no new image and no deployment."
    security.kubeapt.io/resource: "ConfigMaps"
    security.kubeapt.io/severity: "Low"
    security.kubeapt.io/remediation: "Set immutable to true on the ConfigMap and ship changes by creating a new versioned ConfigMap that the workload is repointed to. Field: immutable."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - configmaps
  validations:
  - expression: |
      has(object.immutable) && object.immutable == true
    message: |
      immutable must be set to true to prevent runtime tampering.

Save it as configmap-immutability.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./configmap-immutability.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name configmap-immutability -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name configmap-immutability -A