networkpolicy-allow-all
Selecting every pod with rules that name no peers and no ports unions an allow-all permission across the namespace, which cancels the effect of tighter policies and leaves lateral movement and outbound traffic unconstrained.
!(variables.isAllPods &&
variables.ingressAllowsAll &&
variables.egressAllowsAll)
Wildcard NetworkPolicies that allow all ingress and egress traffic for all pods are not allowed.
isAllPods
(!has(object.spec.podSelector.matchLabels) ||
object.spec.podSelector.matchLabels.size() == 0) &&
(!has(object.spec.podSelector.matchExpressions) ||
object.spec.podSelector.matchExpressions.size() == 0)
ingressAllowsAll
has(object.spec.ingress) && object.spec.ingress.exists(r,
(!has(r.from) || r.from.size() == 0) &&
(!has(r.ports) || r.ports.size() == 0)
)
egressAllowsAll
has(object.spec.egress) && object.spec.egress.exists(r,
(!has(r.to) || r.to.size() == 0) &&
(!has(r.ports) || r.ports.size() == 0)
)
Narrow spec.podSelector to the pods that genuinely need the exemption and give each rule explicit peers and ports. Fields: spec.podSelector, spec.ingress[*].from, spec.ingress[*].ports, spec.egress[*].to, spec.egress[*].ports.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: networkpolicy-allow-all
annotations:
kubeapt.io/uuid: "ff83ae61-3d8a-48b6-9ab0-fd11fd740c33"
security.kubeapt.io/displayName: "Allows All Ingress and Egress for All Pods"
security.kubeapt.io/description: "Selecting every pod with rules that name no peers and no ports unions an allow-all permission across the namespace, which cancels the effect of tighter policies and leaves lateral movement and outbound traffic unconstrained."
security.kubeapt.io/resource: "NetworkPolicies"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Narrow spec.podSelector to the pods that genuinely need the exemption and give each rule explicit peers and ports. Fields: spec.podSelector, spec.ingress[*].from, spec.ingress[*].ports, spec.egress[*].to, spec.egress[*].ports."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- networking.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- networkpolicies
variables:
- name: isAllPods
expression: |
(!has(object.spec.podSelector.matchLabels) ||
object.spec.podSelector.matchLabels.size() == 0) &&
(!has(object.spec.podSelector.matchExpressions) ||
object.spec.podSelector.matchExpressions.size() == 0)
- name: ingressAllowsAll
expression: |
has(object.spec.ingress) && object.spec.ingress.exists(r,
(!has(r.from) || r.from.size() == 0) &&
(!has(r.ports) || r.ports.size() == 0)
)
- name: egressAllowsAll
expression: |
has(object.spec.egress) && object.spec.egress.exists(r,
(!has(r.to) || r.to.size() == 0) &&
(!has(r.ports) || r.ports.size() == 0)
)
validations:
- expression: |
!(variables.isAllPods &&
variables.ingressAllowsAll &&
variables.egressAllowsAll)
message: Wildcard NetworkPolicies that allow all ingress and egress traffic for all pods are not allowed.Save it as networkpolicy-allow-all.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./networkpolicy-allow-all.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name networkpolicy-allow-all -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name networkpolicy-allow-all -A