← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

postStart Hook Targets an Arbitrary Host

initcontainer-poststart-httpget-host

severityLow resourceInitContainers productKubernetes bundles2

A postStart HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node each time an init container starts, reaching internal endpoints closed to pods and triggering side effects there.

Rejects unless

!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
  !has(ic.lifecycle) ||
  !has(ic.lifecycle.postStart) ||
  !has(ic.lifecycle.postStart.httpGet) ||
  !has(ic.lifecycle.postStart.httpGet.host) ||
  ic.lifecycle.postStart.httpGet.host == ""
)

spec.initContainers[*].lifecycle.postStart.httpGet.host must be undefined or empty ("").

Remediation

Remove the host field so the hook targets the pod IP, or set it to an empty string. Field: spec.initContainers[*].lifecycle.postStart.httpGet.host.

Applies to

  • pods · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: initcontainer-poststart-httpget-host
  annotations:
    kubeapt.io/uuid: "fbef4cf3-cf91-4c11-af0b-ab80b64edff8"
    security.kubeapt.io/displayName: "postStart Hook Targets an Arbitrary Host"
    security.kubeapt.io/description: "A postStart HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node each time an init container starts, reaching internal endpoints closed to pods and triggering side effects there."
    security.kubeapt.io/resource: "InitContainers"
    security.kubeapt.io/severity: "Low"
    security.kubeapt.io/remediation: "Remove the host field so the hook targets the pod IP, or set it to an empty string. Field: spec.initContainers[*].lifecycle.postStart.httpGet.host."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods
  validations:
  - expression: |
      !has(object.spec.initContainers) || object.spec.initContainers.all(ic,
        !has(ic.lifecycle) ||
        !has(ic.lifecycle.postStart) ||
        !has(ic.lifecycle.postStart.httpGet) ||
        !has(ic.lifecycle.postStart.httpGet.host) ||
        ic.lifecycle.postStart.httpGet.host == ""
      )
    message: |
      spec.initContainers[*].lifecycle.postStart.httpGet.host must be undefined or empty ("").

Save it as initcontainer-poststart-httpget-host.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./initcontainer-poststart-httpget-host.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name initcontainer-poststart-httpget-host -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name initcontainer-poststart-httpget-host -A