authorizationpolicy-allow-all
An ALLOW rule with no from, to or when matches every request, so the workload accepts any caller inside or outside the mesh while still appearing to be under authorization control.
object.spec.?action.orValue('ALLOW') != 'ALLOW' ||
!object.spec.?rules.orValue([]).exists(r,
!has(r.from) && !has(r.to) && !has(r.when)
)
Istio ALLOW AuthorizationPolicies must not contain a rule with no from/to/when (effectively allow-all).
Add from, to or when conditions naming the permitted principals, namespaces, paths or methods to every ALLOW rule instead of leaving one unconditioned. Fields: spec.rules[*].from, spec.rules[*].to, spec.rules[*].when.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: authorizationpolicy-allow-all
annotations:
kubeapt.io/uuid: "ccc05ad0-3f3d-4ea9-90aa-ce9f0529dc0d"
security.kubeapt.io/displayName: "ALLOW Rule Matches All Requests"
security.kubeapt.io/description: "An ALLOW rule with no from, to or when matches every request, so the workload accepts any caller inside or outside the mesh while still appearing to be under authorization control."
security.kubeapt.io/resource: "AuthorizationPolicies"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Add from, to or when conditions naming the permitted principals, namespaces, paths or methods to every ALLOW rule instead of leaving one unconditioned. Fields: spec.rules[*].from, spec.rules[*].to, spec.rules[*].when."
security.kubeapt.io/product: "Istio"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- security.istio.io
apiVersions:
- v1
- v1beta1
operations:
- CREATE
- UPDATE
resources:
- authorizationpolicies
validations:
- expression: |
object.spec.?action.orValue('ALLOW') != 'ALLOW' ||
!object.spec.?rules.orValue([]).exists(r,
!has(r.from) && !has(r.to) && !has(r.when)
)
message: |
Istio ALLOW AuthorizationPolicies must not contain a rule with no from/to/when (effectively allow-all).Save it as authorizationpolicy-allow-all.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./authorizationpolicy-allow-all.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name authorizationpolicy-allow-all -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name authorizationpolicy-allow-all -A