← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Allows Traffic Across All Namespaces

adminnetworkpolicy-allow-all

severityModerate resourceAdminNetworkPolicies productKubernetes bundles1

An Allow rule with an empty namespaces selector matches every namespace in the cluster, and because AdminNetworkPolicy outranks NetworkPolicy it reopens paths that workload owners deliberately closed.

Rejects unless

!has(object.spec) || (
  !object.spec.?ingress.orValue([]).exists(r,
    r.?action.orValue('') == 'Allow' &&
    r.?from.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
  ) &&
  !object.spec.?egress.orValue([]).exists(r,
    r.?action.orValue('') == 'Allow' &&
    r.?to.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
  )
)

AdminNetworkPolicies must not Allow traffic to/from all namespaces (empty namespace selector).

Remediation

Give each Allow rule a namespaces selector that names the specific namespaces it should cover instead of an empty match-all selector. Fields: spec.ingress[*].from[*].namespaces, spec.egress[*].to[*].namespaces.

Applies to

  • adminnetworkpolicies · policy.networking.k8s.io/v1alpha1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: adminnetworkpolicy-allow-all
  annotations:
    kubeapt.io/uuid: "4de9808c-4b75-4d6a-840a-24ba32e05e5c"
    security.kubeapt.io/displayName: "Allows Traffic Across All Namespaces"
    security.kubeapt.io/description: "An Allow rule with an empty namespaces selector matches every namespace in the cluster, and because AdminNetworkPolicy outranks NetworkPolicy it reopens paths that workload owners deliberately closed."
    security.kubeapt.io/resource: "AdminNetworkPolicies"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Give each Allow rule a namespaces selector that names the specific namespaces it should cover instead of an empty match-all selector. Fields: spec.ingress[*].from[*].namespaces, spec.egress[*].to[*].namespaces."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - policy.networking.k8s.io
      apiVersions:
      - v1alpha1
      operations:
      - CREATE
      - UPDATE
      resources:
      - adminnetworkpolicies
  validations:
  - expression: |
      !has(object.spec) || (
        !object.spec.?ingress.orValue([]).exists(r,
          r.?action.orValue('') == 'Allow' &&
          r.?from.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
        ) &&
        !object.spec.?egress.orValue([]).exists(r,
          r.?action.orValue('') == 'Allow' &&
          r.?to.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
        )
      )
    message: |
      AdminNetworkPolicies must not Allow traffic to/from all namespaces (empty namespace selector).

Save it as adminnetworkpolicy-allow-all.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./adminnetworkpolicy-allow-all.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name adminnetworkpolicy-allow-all -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name adminnetworkpolicy-allow-all -A