ciliumnetworkpolicy-egress-world
The world entity covers every address outside the cluster, so a rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source.
!has(object.spec) || (
!object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
!object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
)
CiliumNetworkPolicies must not allow ingress from or egress to the 'world' entity.
Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: ciliumnetworkpolicy-egress-world
annotations:
kubeapt.io/uuid: "620d1c09-10b1-4b2e-9987-0595e30e45db"
security.kubeapt.io/displayName: "Permits Traffic to the world Entity"
security.kubeapt.io/description: "The world entity covers every address outside the cluster, so a rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source."
security.kubeapt.io/resource: "CiliumNetworkPolicies"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities."
security.kubeapt.io/product: "Cilium"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- cilium.io
apiVersions:
- v2
operations:
- CREATE
- UPDATE
resources:
- ciliumnetworkpolicies
validations:
- expression: |
!has(object.spec) || (
!object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
!object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
)
message: |
CiliumNetworkPolicies must not allow ingress from or egress to the 'world' entity.Save it as ciliumnetworkpolicy-egress-world.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./ciliumnetworkpolicy-egress-world.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name ciliumnetworkpolicy-egress-world -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name ciliumnetworkpolicy-egress-world -A