← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Allows All Ingress and Egress for All Pods

networkpolicy-allow-all

severityModerate resourceNetworkPolicies productKubernetes bundles1

Selecting every pod with rules that name no peers and no ports unions an allow-all permission across the namespace, which cancels the effect of tighter policies and leaves lateral movement and outbound traffic unconstrained.

Rejects unless

!(variables.isAllPods &&
  variables.ingressAllowsAll &&
  variables.egressAllowsAll)

Wildcard NetworkPolicies that allow all ingress and egress traffic for all pods are not allowed.

Variables

isAllPods

(!has(object.spec.podSelector.matchLabels) ||
 object.spec.podSelector.matchLabels.size() == 0) &&
(!has(object.spec.podSelector.matchExpressions) ||
 object.spec.podSelector.matchExpressions.size() == 0)

ingressAllowsAll

has(object.spec.ingress) && object.spec.ingress.exists(r,
  (!has(r.from) || r.from.size() == 0) &&
  (!has(r.ports) || r.ports.size() == 0)
)

egressAllowsAll

has(object.spec.egress) && object.spec.egress.exists(r,
  (!has(r.to) || r.to.size() == 0) &&
  (!has(r.ports) || r.ports.size() == 0)
)

Remediation

Narrow spec.podSelector to the pods that genuinely need the exemption and give each rule explicit peers and ports. Fields: spec.podSelector, spec.ingress[*].from, spec.ingress[*].ports, spec.egress[*].to, spec.egress[*].ports.

Applies to

  • networkpolicies · networking.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: networkpolicy-allow-all
  annotations:
    kubeapt.io/uuid: "ff83ae61-3d8a-48b6-9ab0-fd11fd740c33"
    security.kubeapt.io/displayName: "Allows All Ingress and Egress for All Pods"
    security.kubeapt.io/description: "Selecting every pod with rules that name no peers and no ports unions an allow-all permission across the namespace, which cancels the effect of tighter policies and leaves lateral movement and outbound traffic unconstrained."
    security.kubeapt.io/resource: "NetworkPolicies"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Narrow spec.podSelector to the pods that genuinely need the exemption and give each rule explicit peers and ports. Fields: spec.podSelector, spec.ingress[*].from, spec.ingress[*].ports, spec.egress[*].to, spec.egress[*].ports."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - networking.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - networkpolicies
  variables:
  - name: isAllPods
    expression: |
      (!has(object.spec.podSelector.matchLabels) ||
       object.spec.podSelector.matchLabels.size() == 0) &&
      (!has(object.spec.podSelector.matchExpressions) ||
       object.spec.podSelector.matchExpressions.size() == 0)
  - name: ingressAllowsAll
    expression: |
      has(object.spec.ingress) && object.spec.ingress.exists(r,
        (!has(r.from) || r.from.size() == 0) &&
        (!has(r.ports) || r.ports.size() == 0)
      )
  - name: egressAllowsAll
    expression: |
      has(object.spec.egress) && object.spec.egress.exists(r,
        (!has(r.to) || r.to.size() == 0) &&
        (!has(r.ports) || r.ports.size() == 0)
      )
  validations:
  - expression: |
      !(variables.isAllPods &&
        variables.ingressAllowsAll &&
        variables.egressAllowsAll)
    message: Wildcard NetworkPolicies that allow all ingress and egress traffic for all pods are not allowed.

Save it as networkpolicy-allow-all.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./networkpolicy-allow-all.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name networkpolicy-allow-all -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name networkpolicy-allow-all -A