role-pod-exec-create
Pod write lets the holder run arbitrary images with any service account token in the namespace mounted, while exec, attach, port-forward and ephemeral container access opens a shell into running workloads and their credentials.
!has(object.rules) || object.rules.all(r,
!(
(r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, res == "pods") &&
r.verbs.exists(v, variables.podWriteVerbs.exists(pv, pv == v)))
||
(r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, variables.execResources.exists(er, er == res)) &&
r.verbs.exists(v, v == "create"))
)
)
Roles must not allow pod creation/modification or exec/attach/portforward/ephemeralcontainers access.
podWriteVerbs
["create","update","patch","delete"]
execResources
["pods/exec","pods/attach","pods/portforward","pods/ephemeralcontainers"]
Remove create, update, patch and delete on pods, and the create verb on the pods/exec, pods/attach, pods/portforward and pods/ephemeralcontainers subresources. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: role-pod-exec-create
annotations:
kubeapt.io/uuid: "f9f2c306-ceb8-455e-92a7-c511d3e1f5cb"
security.kubeapt.io/displayName: "Grants Pod Create and Exec Access"
security.kubeapt.io/description: "Pod write lets the holder run arbitrary images with any service account token in the namespace mounted, while exec, attach, port-forward and ephemeral container access opens a shell into running workloads and their credentials."
security.kubeapt.io/resource: "Roles"
security.kubeapt.io/severity: "Critical"
security.kubeapt.io/remediation: "Remove create, update, patch and delete on pods, and the create verb on the pods/exec, pods/attach, pods/portforward and pods/ephemeralcontainers subresources. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- rbac.authorization.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- roles
variables:
- name: podWriteVerbs
expression: |
["create","update","patch","delete"]
- name: execResources
expression: |
["pods/exec","pods/attach","pods/portforward","pods/ephemeralcontainers"]
validations:
- expression: |
!has(object.rules) || object.rules.all(r,
!(
(r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, res == "pods") &&
r.verbs.exists(v, variables.podWriteVerbs.exists(pv, pv == v)))
||
(r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, variables.execResources.exists(er, er == res)) &&
r.verbs.exists(v, v == "create"))
)
)
message: |
Roles must not allow pod creation/modification or exec/attach/portforward/ephemeralcontainers access.Save it as role-pod-exec-create.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./role-pod-exec-create.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name role-pod-exec-create -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name role-pod-exec-create -A