← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

ALLOW Rule Matches All Requests

authorizationpolicy-allow-all

severityModerate resourceAuthorizationPolicies productIstio bundles1

An ALLOW rule with no from, to or when matches every request, so the workload accepts any caller inside or outside the mesh while still appearing to be under authorization control.

Rejects unless

object.spec.?action.orValue('ALLOW') != 'ALLOW' ||
!object.spec.?rules.orValue([]).exists(r,
  !has(r.from) && !has(r.to) && !has(r.when)
)

Istio ALLOW AuthorizationPolicies must not contain a rule with no from/to/when (effectively allow-all).

Remediation

Add from, to or when conditions naming the permitted principals, namespaces, paths or methods to every ALLOW rule instead of leaving one unconditioned. Fields: spec.rules[*].from, spec.rules[*].to, spec.rules[*].when.

Applies to

  • authorizationpolicies · security.istio.io/v1 · CREATE, UPDATE
  • authorizationpolicies · security.istio.io/v1beta1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: authorizationpolicy-allow-all
  annotations:
    kubeapt.io/uuid: "ccc05ad0-3f3d-4ea9-90aa-ce9f0529dc0d"
    security.kubeapt.io/displayName: "ALLOW Rule Matches All Requests"
    security.kubeapt.io/description: "An ALLOW rule with no from, to or when matches every request, so the workload accepts any caller inside or outside the mesh while still appearing to be under authorization control."
    security.kubeapt.io/resource: "AuthorizationPolicies"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Add from, to or when conditions naming the permitted principals, namespaces, paths or methods to every ALLOW rule instead of leaving one unconditioned. Fields: spec.rules[*].from, spec.rules[*].to, spec.rules[*].when."
    security.kubeapt.io/product: "Istio"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - security.istio.io
      apiVersions:
      - v1
      - v1beta1
      operations:
      - CREATE
      - UPDATE
      resources:
      - authorizationpolicies
  validations:
  - expression: |
      object.spec.?action.orValue('ALLOW') != 'ALLOW' ||
      !object.spec.?rules.orValue([]).exists(r,
        !has(r.from) && !has(r.to) && !has(r.when)
      )
    message: |
      Istio ALLOW AuthorizationPolicies must not contain a rule with no from/to/when (effectively allow-all).

Save it as authorizationpolicy-allow-all.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./authorizationpolicy-allow-all.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name authorizationpolicy-allow-all -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name authorizationpolicy-allow-all -A