← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Does Not Require Mutual TLS

peerauthentication-mtls-weakened

severityModerate resourcePeerAuthentications productIstio bundles1

Accepting plaintext connections lets anything that reaches the pod network talk to the service without proving a workload identity, and leaves service-to-service traffic readable and modifiable on the wire.

Rejects unless

!(object.spec.?mtls.mode.orValue('') in ['DISABLE', 'PERMISSIVE']) &&
(!has(object.spec) || !has(object.spec.portLevelMtls) ||
  object.spec.portLevelMtls.all(p,
    !(object.spec.portLevelMtls[p].?mode.orValue('') in ['DISABLE', 'PERMISSIVE'])
  )
)

Istio PeerAuthentications must not disable or weaken mTLS (mode DISABLE or PERMISSIVE).

Remediation

Set the mTLS mode to STRICT at both the workload and the port level so plaintext connections are rejected. Fields: spec.mtls.mode, spec.portLevelMtls[*].mode.

Applies to

  • peerauthentications · security.istio.io/v1 · CREATE, UPDATE
  • peerauthentications · security.istio.io/v1beta1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: peerauthentication-mtls-weakened
  annotations:
    kubeapt.io/uuid: "50c7c898-22c5-4de3-b81e-d4689910780e"
    security.kubeapt.io/displayName: "Does Not Require Mutual TLS"
    security.kubeapt.io/description: "Accepting plaintext connections lets anything that reaches the pod network talk to the service without proving a workload identity, and leaves service-to-service traffic readable and modifiable on the wire."
    security.kubeapt.io/resource: "PeerAuthentications"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Set the mTLS mode to STRICT at both the workload and the port level so plaintext connections are rejected. Fields: spec.mtls.mode, spec.portLevelMtls[*].mode."
    security.kubeapt.io/product: "Istio"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - security.istio.io
      apiVersions:
      - v1
      - v1beta1
      operations:
      - CREATE
      - UPDATE
      resources:
      - peerauthentications
  validations:
  - expression: |
      !(object.spec.?mtls.mode.orValue('') in ['DISABLE', 'PERMISSIVE']) &&
      (!has(object.spec) || !has(object.spec.portLevelMtls) ||
        object.spec.portLevelMtls.all(p,
          !(object.spec.portLevelMtls[p].?mode.orValue('') in ['DISABLE', 'PERMISSIVE'])
        )
      )
    message: |
      Istio PeerAuthentications must not disable or weaken mTLS (mode DISABLE or PERMISSIVE).

Save it as peerauthentication-mtls-weakened.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./peerauthentication-mtls-weakened.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name peerauthentication-mtls-weakened -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name peerauthentication-mtls-weakened -A