apiservice-tls
Skipping certificate verification lets the kube-apiserver proxy aggregated API calls to whatever answers the service endpoint, so anything able to spoof or intercept that connection reads forwarded user identity and returns forged API responses.
!has(object.spec.service) ||
object.spec.?insecureSkipTLSVerify.orValue(false) != true
Aggregated (service-backed) APIServices must not set insecureSkipTLSVerify to true.
Set spec.insecureSkipTLSVerify to false and instead pin the CA that signed the extension API server certificate in spec.caBundle. Field: spec.insecureSkipTLSVerify.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: apiservice-tls
annotations:
kubeapt.io/uuid: "d97253ad-f3dd-4721-b40e-944d2ae07159"
security.kubeapt.io/displayName: "Skips TLS Verification to the Backing Service"
security.kubeapt.io/description: "Skipping certificate verification lets the kube-apiserver proxy aggregated API calls to whatever answers the service endpoint, so anything able to spoof or intercept that connection reads forwarded user identity and returns forged API responses."
security.kubeapt.io/resource: "APIServices"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Set spec.insecureSkipTLSVerify to false and instead pin the CA that signed the extension API server certificate in spec.caBundle. Field: spec.insecureSkipTLSVerify."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- apiregistration.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- apiservices
validations:
- expression: |
!has(object.spec.service) ||
object.spec.?insecureSkipTLSVerify.orValue(false) != true
message: |
Aggregated (service-backed) APIServices must not set insecureSkipTLSVerify to true.Save it as apiservice-tls.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./apiservice-tls.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name apiservice-tls -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name apiservice-tls -A