← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Skips TLS Verification to the Backing Service

apiservice-tls

severityModerate resourceAPIServices productKubernetes bundles1

Skipping certificate verification lets the kube-apiserver proxy aggregated API calls to whatever answers the service endpoint, so anything able to spoof or intercept that connection reads forwarded user identity and returns forged API responses.

Rejects unless

!has(object.spec.service) ||
object.spec.?insecureSkipTLSVerify.orValue(false) != true

Aggregated (service-backed) APIServices must not set insecureSkipTLSVerify to true.

Remediation

Set spec.insecureSkipTLSVerify to false and instead pin the CA that signed the extension API server certificate in spec.caBundle. Field: spec.insecureSkipTLSVerify.

Applies to

  • apiservices · apiregistration.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: apiservice-tls
  annotations:
    kubeapt.io/uuid: "d97253ad-f3dd-4721-b40e-944d2ae07159"
    security.kubeapt.io/displayName: "Skips TLS Verification to the Backing Service"
    security.kubeapt.io/description: "Skipping certificate verification lets the kube-apiserver proxy aggregated API calls to whatever answers the service endpoint, so anything able to spoof or intercept that connection reads forwarded user identity and returns forged API responses."
    security.kubeapt.io/resource: "APIServices"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Set spec.insecureSkipTLSVerify to false and instead pin the CA that signed the extension API server certificate in spec.caBundle. Field: spec.insecureSkipTLSVerify."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - apiregistration.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - apiservices
  validations:
  - expression: |
      !has(object.spec.service) ||
      object.spec.?insecureSkipTLSVerify.orValue(false) != true
    message: |
      Aggregated (service-backed) APIServices must not set insecureSkipTLSVerify to true.

Save it as apiservice-tls.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./apiservice-tls.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name apiservice-tls -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name apiservice-tls -A