ephemeralcontainer-seccomp-profile
An Unconfined seccomp profile removes the syscall filter from the ephemeral container, typically attached with kubectl debug, exposing the full kernel syscall surface including the obscure calls that container escape and privilege-escalation exploits depend on.
(has(object.spec.os) &&
has(object.spec.os.name) &&
object.spec.os.name.lowerAscii() == "windows") ||
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
!has(ec.securityContext) ||
!has(ec.securityContext.seccompProfile) ||
!has(ec.securityContext.seccompProfile.type) ||
variables.allowedSeccompTypes.exists(t, t == ec.securityContext.seccompProfile.type)
)
spec.ephemeralContainers[*].securityContext.seccompProfile.type must be undefined, RuntimeDefault, or Localhost.
allowedSeccompTypes
["RuntimeDefault","Localhost"]
Replace Unconfined with RuntimeDefault, or with Localhost naming a profile loaded on the node. Field: spec.ephemeralContainers[*].securityContext.seccompProfile.type.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: ephemeralcontainer-seccomp-profile
annotations:
kubeapt.io/uuid: "a8381fc3-c338-4365-9a3f-1b28eb7e16f2"
security.kubeapt.io/displayName: "Runs With an Unconfined Seccomp Profile"
security.kubeapt.io/description: "An Unconfined seccomp profile removes the syscall filter from the ephemeral container, typically attached with kubectl debug, exposing the full kernel syscall surface including the obscure calls that container escape and privilege-escalation exploits depend on."
security.kubeapt.io/resource: "EphemeralContainers"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Replace Unconfined with RuntimeDefault, or with Localhost naming a profile loaded on the node. Field: spec.ephemeralContainers[*].securityContext.seccompProfile.type."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods/ephemeralcontainers
variables:
- name: allowedSeccompTypes
expression: |
["RuntimeDefault","Localhost"]
validations:
- expression: |
(has(object.spec.os) &&
has(object.spec.os.name) &&
object.spec.os.name.lowerAscii() == "windows") ||
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
!has(ec.securityContext) ||
!has(ec.securityContext.seccompProfile) ||
!has(ec.securityContext.seccompProfile.type) ||
variables.allowedSeccompTypes.exists(t, t == ec.securityContext.seccompProfile.type)
)
message: |
spec.ephemeralContainers[*].securityContext.seccompProfile.type must be undefined, RuntimeDefault, or Localhost.Save it as ephemeralcontainer-seccomp-profile.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./ephemeralcontainer-seccomp-profile.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-seccomp-profile -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name ephemeralcontainer-seccomp-profile -A