← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Grants get on nodes/proxy (Kubelet API)

clusterrole-nodes-proxy-get

severityHigh resourceClusterRoles productKubernetes bundles1

Get on the node proxy subresource forwards requests straight to the kubelet API, exposing the pod inventory, container logs and runtime detail of every workload scheduled on that node.

Rejects unless

!has(object.rules) || object.rules.all(r,
  !(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
    r.apiGroups.exists(ag, ag == "") &&
    r.resources.exists(res, res == "nodes/proxy") &&
    r.verbs.exists(v, v == "get")
  )
)

ClusterRoles must not grant get access to nodes/proxy.

Remediation

Remove the get verb for nodes/proxy in the core API group and read workload data through the pods and pods/log APIs instead. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs.

Applies to

  • clusterroles · rbac.authorization.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: clusterrole-nodes-proxy-get
  annotations:
    kubeapt.io/uuid: "83c49431-dc09-4340-9d03-fe99349e6d3a"
    security.kubeapt.io/displayName: "Grants get on nodes/proxy (Kubelet API)"
    security.kubeapt.io/description: "Get on the node proxy subresource forwards requests straight to the kubelet API, exposing the pod inventory, container logs and runtime detail of every workload scheduled on that node."
    security.kubeapt.io/resource: "ClusterRoles"
    security.kubeapt.io/severity: "High"
    security.kubeapt.io/remediation: "Remove the get verb for nodes/proxy in the core API group and read workload data through the pods and pods/log APIs instead. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - rbac.authorization.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - clusterroles
  validations:
  - expression: |
      !has(object.rules) || object.rules.all(r,
        !(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
          r.apiGroups.exists(ag, ag == "") &&
          r.resources.exists(res, res == "nodes/proxy") &&
          r.verbs.exists(v, v == "get")
        )
      )
    message: |
      ClusterRoles must not grant get access to nodes/proxy.

Save it as clusterrole-nodes-proxy-get.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./clusterrole-nodes-proxy-get.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name clusterrole-nodes-proxy-get -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name clusterrole-nodes-proxy-get -A