← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Provisions Unencrypted Ceph RBD Volumes

storageclass-encryption-ceph-rbd

severityLow resourceStorageClasses productKubernetes bundles1

Volumes provisioned from this class land on unencrypted RBD images, so anyone with access to the Ceph pool, an image snapshot or the backing OSD disks reads the data without any Kubernetes access.

Rejects unless

object.provisioner != 'rbd.csi.ceph.com' ||
(has(object.parameters) && 'encrypted' in object.parameters &&
 object.parameters['encrypted'] == 'true')

Ceph RBD StorageClasses must enable at-rest encryption (parameters.encrypted: "true").

Remediation

Set parameters.encrypted to true on rbd.csi.ceph.com StorageClasses and point parameters.encryptionKMSID at the configured KMS entry. Field: parameters.encrypted.

Applies to

  • storageclasses · storage.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: storageclass-encryption-ceph-rbd
  annotations:
    kubeapt.io/uuid: "f9881fc5-db3d-4cd5-9788-f6529f0f853e"
    security.kubeapt.io/displayName: "Provisions Unencrypted Ceph RBD Volumes"
    security.kubeapt.io/description: "Volumes provisioned from this class land on unencrypted RBD images, so anyone with access to the Ceph pool, an image snapshot or the backing OSD disks reads the data without any Kubernetes access."
    security.kubeapt.io/resource: "StorageClasses"
    security.kubeapt.io/severity: "Low"
    security.kubeapt.io/remediation: "Set parameters.encrypted to true on rbd.csi.ceph.com StorageClasses and point parameters.encryptionKMSID at the configured KMS entry. Field: parameters.encrypted."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - storage.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - storageclasses
  validations:
  - expression: |
      object.provisioner != 'rbd.csi.ceph.com' ||
      (has(object.parameters) && 'encrypted' in object.parameters &&
       object.parameters['encrypted'] == 'true')
    message: |
      Ceph RBD StorageClasses must enable at-rest encryption (parameters.encrypted: "true").

Save it as storageclass-encryption-ceph-rbd.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./storageclass-encryption-ceph-rbd.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name storageclass-encryption-ceph-rbd -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name storageclass-encryption-ceph-rbd -A