rolebinding-powerful-roles
Roles like cluster-admin, admin and edit carry sweeping verbs across nearly every API resource, so one compromised subject in the binding gains full control of the namespace and its secrets.
!has(object.roleRef) || !(object.roleRef.kind in ["ClusterRole","Role"] &&
variables.powerfulRoles.exists(rn, rn == object.roleRef.name))
RoleBindings must not reference powerful roles such as cluster-admin/admin/edit.
powerfulRoles
["cluster-admin","admin","edit","ns-admin","full-access"]
Point roleRef at a purpose-built role that lists only the resources and verbs the subject needs. Fields: roleRef.kind, roleRef.name.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: rolebinding-powerful-roles
annotations:
kubeapt.io/uuid: "c0fb63ca-f7fc-4f04-b552-83c54f503fef"
security.kubeapt.io/displayName: "Binds a Privileged Role Such as cluster-admin"
security.kubeapt.io/description: "Roles like cluster-admin, admin and edit carry sweeping verbs across nearly every API resource, so one compromised subject in the binding gains full control of the namespace and its secrets."
security.kubeapt.io/resource: "RoleBindings"
security.kubeapt.io/severity: "High"
security.kubeapt.io/remediation: "Point roleRef at a purpose-built role that lists only the resources and verbs the subject needs. Fields: roleRef.kind, roleRef.name."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- rbac.authorization.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- rolebindings
variables:
- name: powerfulRoles
expression: |
["cluster-admin","admin","edit","ns-admin","full-access"]
validations:
- expression: |
!has(object.roleRef) || !(object.roleRef.kind in ["ClusterRole","Role"] &&
variables.powerfulRoles.exists(rn, rn == object.roleRef.name))
message: |
RoleBindings must not reference powerful roles such as cluster-admin/admin/edit.Save it as rolebinding-powerful-roles.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./rolebinding-powerful-roles.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name rolebinding-powerful-roles -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name rolebinding-powerful-roles -A