← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Permits Privilege Escalation

ephemeralcontainer-privilege-escalation

severityHigh resourceEphemeralContainers productKubernetes bundles2

Leaving privilege escalation enabled lets a process in the ephemeral container gain more privileges than its parent through setuid binaries or file capabilities, turning a compromised unprivileged process into root inside the container.

Rejects unless

(has(object.spec.os) &&
 has(object.spec.os.name) &&
 object.spec.os.name.lowerAscii() == "windows") ||
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
  has(ec.securityContext) &&
  has(ec.securityContext.allowPrivilegeEscalation) &&
  ec.securityContext.allowPrivilegeEscalation == false
)

spec.ephemeralContainers[*].securityContext.allowPrivilegeEscalation must be set to false.

Remediation

Set allowPrivilegeEscalation to false in the security context of every ephemeral container. The field must be present explicitly, since omitting it also fails. Field: spec.ephemeralContainers[*].securityContext.allowPrivilegeEscalation.

Applies to

  • pods/ephemeralcontainers · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ephemeralcontainer-privilege-escalation
  annotations:
    kubeapt.io/uuid: "5a3050eb-06b6-4eff-88db-e9bcd5ab38f7"
    security.kubeapt.io/displayName: "Permits Privilege Escalation"
    security.kubeapt.io/description: "Leaving privilege escalation enabled lets a process in the ephemeral container gain more privileges than its parent through setuid binaries or file capabilities, turning a compromised unprivileged process into root inside the container."
    security.kubeapt.io/resource: "EphemeralContainers"
    security.kubeapt.io/severity: "High"
    security.kubeapt.io/remediation: "Set allowPrivilegeEscalation to false in the security context of every ephemeral container. The field must be present explicitly, since omitting it also fails. Field: spec.ephemeralContainers[*].securityContext.allowPrivilegeEscalation."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods/ephemeralcontainers
  validations:
  - expression: |
      (has(object.spec.os) &&
       has(object.spec.os.name) &&
       object.spec.os.name.lowerAscii() == "windows") ||
      !has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
        has(ec.securityContext) &&
        has(ec.securityContext.allowPrivilegeEscalation) &&
        ec.securityContext.allowPrivilegeEscalation == false
      )
    message: |
      spec.ephemeralContainers[*].securityContext.allowPrivilegeEscalation must be set to false.

Save it as ephemeralcontainer-privilege-escalation.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ephemeralcontainer-privilege-escalation.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-privilege-escalation -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ephemeralcontainer-privilege-escalation -A