</> Policy library · Apache-2.0

policies

Curated ValidatingAdmissionPolicies for Kubernetes, written in CEL and severity-rated. There is no Kyverno or OPA to run: these are native Kubernetes objects. Install them with kubeapt, or apply them straight with kubectl.

policies193 admission176 bundles2 licenseApache-2.0
// bundles

two curated bundles.

A bundle is a versioned set of policies plus the bindings that switch them on. Label a namespace to activate one — start in warn, move to audit, then enforce. Compare both bundles →

cenroq Best Practices

v0.2.0

Best practice validating admission bundle that enforces pod hardening, safer runtime defaults, and broader cluster guardrails (RBAC, secrets, exposure, and risky config restrictions) for a strong security baseline.

176 policies528 bindings176 of 176 bound
  • 16 Critical
  • 27 High
  • 99 Moderate
  • 34 Low

Pod Security Admission

v1.36.0-cenroq

Pod Security Standards implemented as Validating Admission Policies, with the same levels (baseline and restricted).

84 policies252 bindings84 of 84 bound
  • 4 Critical
  • 14 High
  • 46 Moderate
  • 20 Low
// catalog

every policy, one card each.

Filter by type, severity, resource, product or bundle, or search the text — the search reaches the CEL too, even though the expression itself lives on each policy's own page. Open a card for the expression that enforces it, the message it rejects with, how to fix a violation, the full manifest, and the kubeapt validate line that checks a workload against it.

The Istio and NetworkPolicy entries are in the same list, marked Example: reference manifests to copy and adapt, not rules we enforce for you. They carry no severity and belong to no bundle. Filter them in or out under Type.

Filtering, search and paging need JavaScript. Without it every entry in the library is listed below at once, and every card still links to its own page.

Severity
193 policies
CriticalClusterRoles · Kubernetes

Grants Approval of Certificate Signing Requests

clusterrole-cert-auth-review

Write access to certificate signing requests and to the authorization and authentication review APIs lets the holder issue client certificates and use the API server to test which permissions a stolen credential carries.

ValidatingAdmissionPolicy · 1 bundle
CriticalClusterRoles · Kubernetes

Grants Pod Create and Exec Access

clusterrole-pod-exec-create

Pod write lets the holder run arbitrary images with any service account token in the cluster mounted, while exec, attach, port-forward and ephemeral container access opens a shell into running workloads and their credentials.

ValidatingAdmissionPolicy · 1 bundle
CriticalClusterRoles · Kubernetes

Grants the impersonate Verb

clusterrole-rbac-impersonate

Impersonation lets the holder send requests as any other user, group or service account, borrowing the permissions of cluster-admin identities without ever being granted those permissions in its own bindings.

ValidatingAdmissionPolicy · 1 bundle
CriticalClusterRoles · Kubernetes

Grants Access to Secrets

clusterrole-secrets-access

Reading Secrets exposes the credentials they hold in every namespace, including service account tokens, TLS private keys and registry passwords, and the write verbs let those values be replaced with attacker-controlled ones.

ValidatingAdmissionPolicy · 1 bundle
CriticalClusterRoles · Kubernetes

Grants Creation of ServiceAccount Tokens

clusterrole-serviceaccount-tokens

Creating the token subresource mints a working bearer token for any service account in the cluster, letting the holder act as the most privileged one and reuse that token from outside the cluster.

ValidatingAdmissionPolicy · 1 bundle
CriticalClusterRoles · Kubernetes

Uses Wildcard apiGroups, Resources or Verbs

clusterrole-wildcard-rules

A wildcard in apiGroups, resources or verbs hands over an entire API group, every resource type or every operation on them across the cluster, and silently widens to each CRD installed later.

ValidatingAdmissionPolicy · 1 bundle
CriticalConfigMaps · Kubernetes

Stores Credentials, Tokens or Private Keys

configmap-secrets

Credentials in a ConfigMap are stored unencrypted and readable by anyone holding the broad ConfigMap read permission most roles grant, and they leak further through logs, backups and manifests in source control.

ValidatingAdmissionPolicy · 1 bundle
CriticalContainers · Kubernetes

Runs in Privileged Mode

container-privileged

A privileged container disables almost all container isolation and gets full root access to the node devices, kernel interfaces and filesystem, which is a direct path to node and cluster takeover.

ValidatingAdmissionPolicy · 2 bundles
CriticalEphemeralContainers · Kubernetes

Runs in Privileged Mode

ephemeralcontainer-privileged

A privileged ephemeral container disables almost all container isolation and gets full root access to the node devices, kernel interfaces and filesystem, which is a direct path to node and cluster takeover.

ValidatingAdmissionPolicy · 2 bundles
CriticalInitContainers · Kubernetes

Runs in Privileged Mode

initcontainer-privileged

A privileged init container disables almost all container isolation and gets full root access to the node devices, kernel interfaces and filesystem, which is a direct path to node and cluster takeover.

ValidatingAdmissionPolicy · 2 bundles
CriticalPods · Kubernetes

Mounts a hostPath Volume From the Node

pod-hostpath-volumes

A hostPath volume mounts node filesystem paths into the pod, exposing kubelet credentials, container runtime sockets and other workload data, and a writable mount lets an attacker alter node files to take over the node.

ValidatingAdmissionPolicy · 2 bundles
CriticalRoles · Kubernetes

Grants Pod Create and Exec Access

role-pod-exec-create

Pod write lets the holder run arbitrary images with any service account token in the namespace mounted, while exec, attach, port-forward and ephemeral container access opens a shell into running workloads and their credentials.

ValidatingAdmissionPolicy · 1 bundle
CriticalRoles · Kubernetes

Grants the impersonate Verb

role-rbac-impersonate

Impersonation lets the holder send requests as any other user, group or service account, borrowing the permissions of far more privileged identities without ever being granted those permissions in its own bindings.

ValidatingAdmissionPolicy · 1 bundle
CriticalRoles · Kubernetes

Grants Access to Secrets

role-secrets-access

Reading Secrets exposes the credentials they hold in the namespace, including service account tokens, TLS private keys and registry passwords, and the write verbs let those values be replaced with attacker-controlled ones.

ValidatingAdmissionPolicy · 1 bundle
CriticalRoles · Kubernetes

Grants Creation of ServiceAccount Tokens

role-serviceaccount-tokens

Creating the token subresource mints a working bearer token for any service account in the namespace, letting the holder act as the most privileged one and reuse that token from outside the cluster.

ValidatingAdmissionPolicy · 1 bundle
CriticalRoles · Kubernetes

Uses Wildcard apiGroups, Resources or Verbs

role-wildcard-rules

A wildcard in apiGroups, resources or verbs hands over an entire API group, every resource type or every operation on them within the namespace, and silently widens to each CRD installed later.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoles · Kubernetes

Grants Write Access to Admission Webhooks

clusterrole-admission-api-control

Write access to webhook configurations lets the holder delete or rewrite admission control itself, disabling every policy that guards the cluster and mutating arbitrary objects as they are admitted.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoles · Kubernetes

Grants Broad Access to Nodes and Cluster Storage

clusterrole-infra-cluster-resources

Reading or proxying nodes exposes kubelet endpoints and every workload placed on them, while write access to persistent volumes, storage classes and namespaces lets a caller mount host paths and stage pods outside guarded namespaces.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoles · Kubernetes

Grants get on nodes/proxy (Kubelet API)

clusterrole-nodes-proxy-get

Get on the node proxy subresource forwards requests straight to the kubelet API, exposing the pod inventory, container logs and runtime detail of every workload scheduled on that node.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoles · Kubernetes

Grants Write Access to RBAC Resources

clusterrole-rbac-write

Write, bind or escalate permission over RBAC objects lets the grantee author new roles and bindings for itself, turning a limited account into cluster-admin without stealing any other credential.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoles · Kubernetes

Grants Write Access to ServiceAccounts

clusterrole-serviceaccounts-write

Creating or replacing ServiceAccounts anywhere in the cluster lets an attacker re-create an identity that existing bindings already point at and take over its tokens, inheriting every permission bound to that name.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoles · Kubernetes

Grants Write Access to Workload Controllers

clusterrole-workloads-write

Write access to workload controllers becomes arbitrary pod creation through the controller, letting the holder run any image under any service account in the cluster and, with DaemonSets, land that container on every node.

ValidatingAdmissionPolicy · 1 bundle
HighClusterRoleBindings · Kubernetes

Binds a Privileged Role Such as cluster-admin

clusterrolebinding-powerful-roles

Roles like cluster-admin, admin and edit carry sweeping verbs across nearly every API resource, so one compromised subject in the binding gains full control of the cluster and every secret in it.

ValidatingAdmissionPolicy · 1 bundle
HighContainers · Kubernetes

Permits Privilege Escalation

container-privilege-escalation

Leaving privilege escalation enabled lets a process in the container gain more privileges than its parent through setuid binaries or file capabilities, turning a compromised unprivileged process into root inside the container.

ValidatingAdmissionPolicy · 2 bundles
HighContainers · Kubernetes

Uses an Unmasked /proc Mount

container-procmount

An unmasked /proc strips the default masks and read-only paths the runtime applies, exposing kernel memory and tunables such as /proc/kcore and /proc/sys to the container and easing container escape.

ValidatingAdmissionPolicy · 2 bundles
HighContainers · Kubernetes

Runs as a Windows HostProcess

container-windows-hostprocess

A Windows HostProcess container runs directly on the node in the host namespaces under a system account, exposing the host filesystem, registry and services and making node compromise trivial.

ValidatingAdmissionPolicy · 2 bundles
HighEphemeralContainers · Kubernetes

Permits Privilege Escalation

ephemeralcontainer-privilege-escalation

Leaving privilege escalation enabled lets a process in the ephemeral container gain more privileges than its parent through setuid binaries or file capabilities, turning a compromised unprivileged process into root inside the container.

ValidatingAdmissionPolicy · 2 bundles
HighEphemeralContainers · Kubernetes

Uses an Unmasked /proc Mount

ephemeralcontainer-procmount

An unmasked /proc strips the default masks and read-only paths the runtime applies, exposing kernel memory and tunables such as /proc/kcore and /proc/sys to the ephemeral container and easing container escape.

ValidatingAdmissionPolicy · 2 bundles
HighEphemeralContainers · Kubernetes

Runs as a Windows HostProcess

ephemeralcontainer-windows-hostprocess

A Windows HostProcess ephemeral container runs directly on the node in the host namespaces under a system account, exposing the host filesystem, registry and services and making node compromise trivial.

ValidatingAdmissionPolicy · 2 bundles
HighInitContainers · Kubernetes

Permits Privilege Escalation

initcontainer-privilege-escalation

Leaving privilege escalation enabled lets a process in the init container gain more privileges than its parent through setuid binaries or file capabilities, turning a compromised unprivileged process into root inside the container.

ValidatingAdmissionPolicy · 2 bundles
HighInitContainers · Kubernetes

Uses an Unmasked /proc Mount

initcontainer-procmount

An unmasked /proc strips the default masks and read-only paths the runtime applies, exposing kernel memory and tunables such as /proc/kcore and /proc/sys to the init container and easing container escape.

ValidatingAdmissionPolicy · 2 bundles
HighInitContainers · Kubernetes

Runs as a Windows HostProcess

initcontainer-windows-hostprocess

A Windows HostProcess init container runs directly on the node in the host namespaces under a system account, exposing the host filesystem, registry and services and making node compromise trivial.

ValidatingAdmissionPolicy · 2 bundles
HighPersistentVolumes · Kubernetes

Is Backed by a Node-Local hostPath Volume

persistentvolume-hostpath

A hostPath or local PersistentVolume hands pods a path on the node filesystem, so any workload that binds the claim can read or tamper with kubelet credentials and other tenants' data.

ValidatingAdmissionPolicy · 1 bundle
HighPods · Kubernetes

Shares the Host IPC Namespace

pod-hostipc

Sharing the host IPC namespace exposes the node shared memory segments, semaphores and message queues to the container, letting it read in-memory data and tamper with host processes and other pods that share it.

ValidatingAdmissionPolicy · 2 bundles
HighPods · Kubernetes

Shares the Host Network Namespace

pod-hostnetwork

Host networking removes network namespace isolation, letting the workload sniff all node traffic, bind directly to node ports and reach loopback-bound node services such as the kubelet and local metadata proxies.

ValidatingAdmissionPolicy · 2 bundles
HighPods · Kubernetes

Shares the Host PID Namespace

pod-hostpid

Sharing the host PID namespace exposes every process on the node to the container, leaking credentials from process command lines and /proc and letting it signal or trace host and other tenant workloads.

ValidatingAdmissionPolicy · 2 bundles
HighPods · Kubernetes

Shares the Host User Namespace

pod-hostusers

Running in the host user namespace removes UID remapping, so container root is real root on the node and any escape or shared host resource is entered with full node privileges.

ValidatingAdmissionPolicy · 1 bundle
HighPods · Kubernetes

Uses a Volume Type Outside the Allowed Set

pod-volume-types

Volume sources outside the allowed set, such as hostPath, gitRepo or flexVolume, mount node filesystem paths or run driver code on the node, opening a route to kubelet credentials and the container runtime socket.

ValidatingAdmissionPolicy · 2 bundles
HighPods · Kubernetes

Runs as a Windows HostProcess

pod-windows-hostprocess

A Windows HostProcess pod runs its containers directly on the node in the host namespaces under a system account, exposing the host filesystem, registry and services and making node compromise trivial.

ValidatingAdmissionPolicy · 2 bundles
HighRoles · Kubernetes

Grants Write Access to RBAC Resources

role-rbac-write

Write, bind or escalate permission over RBAC objects lets the grantee author new roles and bindings for itself, turning a limited account into full control of the namespace without stealing any other credential.

ValidatingAdmissionPolicy · 1 bundle
HighRoles · Kubernetes

Grants Write Access to ServiceAccounts

role-serviceaccounts-write

Creating or replacing ServiceAccounts in the namespace lets an attacker re-create an identity that existing bindings already point at and take over its tokens, inheriting every permission bound to that name.

ValidatingAdmissionPolicy · 1 bundle
HighRoles · Kubernetes

Grants Write Access to Workload Controllers

role-workloads-write

Write access to workload controllers becomes arbitrary pod creation through the controller, letting the holder run any image under any service account in the namespace and, with DaemonSets, land that container on every node.

ValidatingAdmissionPolicy · 1 bundle
HighRoleBindings · Kubernetes

Binds a Privileged Role Such as cluster-admin

rolebinding-powerful-roles

Roles like cluster-admin, admin and edit carry sweeping verbs across nearly every API resource, so one compromised subject in the binding gains full control of the namespace and its secrets.

ValidatingAdmissionPolicy · 1 bundle
ModerateAdminNetworkPolicies · Kubernetes

Allows Traffic Across All Namespaces

adminnetworkpolicy-allow-all

An Allow rule with an empty namespaces selector matches every namespace in the cluster, and because AdminNetworkPolicy outranks NetworkPolicy it reopens paths that workload owners deliberately closed.

ValidatingAdmissionPolicy · 1 bundle
ModerateAPIServices · Kubernetes

Skips TLS Verification to the Backing Service

apiservice-tls

Skipping certificate verification lets the kube-apiserver proxy aggregated API calls to whatever answers the service endpoint, so anything able to spoof or intercept that connection reads forwarded user identity and returns forged API responses.

ValidatingAdmissionPolicy · 1 bundle
ModerateAuthorizationPolicies · Istio

ALLOW Rule Matches All Requests

authorizationpolicy-allow-all

An ALLOW rule with no from, to or when matches every request, so the workload accepts any caller inside or outside the mesh while still appearing to be under authorization control.

ValidatingAdmissionPolicy · 1 bundle
ModerateBaselineAdminNetworkPolicies · Kubernetes

Allows Traffic Across All Namespaces

baselineadminnetworkpolicy-allow-all

An Allow rule with an empty namespaces selector matches every namespace in the cluster, so any traffic that no NetworkPolicy or AdminNetworkPolicy decides falls back to being permitted rather than dropped.

ValidatingAdmissionPolicy · 1 bundle
ModerateCiliumClusterwideNetworkPolicies · Cilium

Permits Traffic to the world Entity

ciliumclusterwidenetworkpolicy-egress-world

The world entity covers every address outside the cluster, so a cluster-wide rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source.

ValidatingAdmissionPolicy · 1 bundle
ModerateCiliumNetworkPolicies · Cilium

Permits Traffic to the world Entity

ciliumnetworkpolicy-egress-world

The world entity covers every address outside the cluster, so a rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterPolicies · Kyverno

Audits Instead of Enforcing Violations

clusterpolicy-kyverno-not-enforcing

A ClusterPolicy left on Audit only records violations in a report, so the workloads it was written to block are admitted cluster-wide anyway and the protection exists only as a log entry.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterRoles · Kubernetes

Uses an Aggregation Rule to Inherit Permissions

clusterrole-aggregation

An aggregated ClusterRole silently absorbs the rules of every ClusterRole carrying a matching label, so anyone able to create a labeled role grows its permissions with no review of the binding.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterRoles · Kubernetes

Grants Broad Non-Resource URL Access

clusterrole-nonresource-urls

Wildcard or root non-resource paths grant every API server endpoint outside the resource model, so /logs serves node file contents and /debug/pprof heap dumps that carry in-flight credentials straight to the role holder.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterRoles · Kubernetes

Grants Write Access to PersistentVolumeClaims

clusterrole-pvc-write

Creating PersistentVolumeClaims in any namespace can bind a volume that still holds data from another workload into an attacker-controlled pod, while delete destroys the backing data and unbounded provisioning exhausts the storage quota.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterRoleBindings · Kubernetes

Binds a Role to an Anonymous Identity

clusterrolebinding-anonymous-subjects

Binding a ClusterRole to system:anonymous grants it cluster-wide to every unauthenticated caller that reaches the API server, and catch-all names like everyone or all-users leave nobody accountable for who exercises it.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterRoleBindings · Kubernetes

Binds a Privileged Role to the Default ServiceAccount

clusterrolebinding-default-serviceaccount

Every pod that names no ServiceAccount runs as default, so a ClusterRoleBinding to it spreads cluster-wide permissions across unrelated workloads in that namespace and any single compromised container inherits them immediately.

ValidatingAdmissionPolicy · 1 bundle
ModerateClusterRoleBindings · Kubernetes

Binds a Privileged Role to a System Group

clusterrolebinding-system-groups

Binding a ClusterRole to a system group grants it cluster-wide to a whole population at once, and groups like system:authenticated or system:serviceaccounts cover every account in the cluster including ones an attacker controls.

ValidatingAdmissionPolicy · 1 bundle
ModerateConfigMaps · Kubernetes

Stores Executable Code or Scripts

configmap-executable-code

Scripts stored in a ConfigMap and executed by a pod turn ConfigMap write access into code execution inside the container, bypassing image scanning, image signing and any review of what actually runs.

ValidatingAdmissionPolicy · 1 bundle
ModerateContainers · Kubernetes

Runs With an Unconfined AppArmor Profile

container-apparmor-profile

An Unconfined AppArmor profile strips the mandatory access controls over file, capability and mount operations in the container, widening what a compromised process can reach on the host.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Adds a Capability Outside the Baseline Set

container-capabilities-add

Linux capabilities beyond the baseline set, such as SYS_ADMIN, SYS_MODULE, SYS_PTRACE or NET_RAW, hand a container kernel level privileges it can use to mount filesystems, load modules and break out onto the node.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Adds a Capability Other Than NET_BIND_SERVICE

container-capabilities-add-netbindservice

Added capabilities other than NET_BIND_SERVICE give a container kernel privileges such as raw socket access, process tracing and filesystem mounting, extending its reach past its namespace onto the node.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Retains Default Linux Capabilities

container-capabilities-drop-all

A container that never drops ALL keeps the default runtime capability set, so code execution inside it inherits DAC_OVERRIDE, SETUID and NET_RAW for bypassing file permissions, regaining root and spoofing traffic.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Binds a hostPort on the Node

container-hostports

A hostPort binds the container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Runs an Image Not Pinned to a Digest

container-image-digest

An image reference without a digest resolves through a mutable tag, so registry content can be replaced between pulls and the container silently starts running attacker-supplied code on the next restart or reschedule.

ValidatingAdmissionPolicy · 1 bundle
ModerateContainers · Kubernetes

Runs an Image Tagged latest

container-image-tag

Untagged and latest references float to whatever was pushed to the registry most recently, so a restart or reschedule can pull unreviewed or poisoned code into the container without any spec change.

ValidatingAdmissionPolicy · 1 bundle
ModerateContainers · Kubernetes

Runs With a Writable Root Filesystem

container-read-only-root-filesystem

A writable container root filesystem lets an intruder drop tooling, overwrite application binaries, and rewrite configuration in place, leaving a foothold in the running pod that nothing in the image would reveal.

ValidatingAdmissionPolicy · 1 bundle
ModerateContainers · Kubernetes

Runs With the Root Group (GID 0)

container-run-as-group

A container running with GID 0 places its processes in the root group, which owns or can write many files in images and mounted host volumes, widening what a compromised process reaches.

ValidatingAdmissionPolicy · 1 bundle
ModerateContainers · Kubernetes

May Run as Root

container-run-as-nonroot

With runAsNonRoot unset, the kubelet never rejects an image whose user is UID 0, so the container silently runs as root and any compromise gains root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Runs as Root (UID 0)

container-run-as-user

Running a container as UID 0 gives every process the in-container root identity, so writable host mounts, setuid binaries and isolation weaknesses become exploitable with root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Runs With an Unconfined Seccomp Profile

container-seccomp-profile

An Unconfined seccomp profile removes the syscall filter from the container, exposing the full kernel syscall surface including the obscure calls that container escape and privilege-escalation exploits depend on.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Has No Seccomp Profile Set

container-seccomp-profile-restricted

A container with no seccomp profile enforced at pod or container level runs with no syscall filter, leaving the full kernel syscall surface reachable for container escape and privilege escalation.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Sets a Custom SELinux Role

container-selinux-role

A custom SELinux role label lets the container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Sets a Non-Standard SELinux Type

container-selinux-type

An SELinux type outside the container domains, such as spc_t or unconfined_t, drops the kernel confinement that stops a container process from reading host files and reaching devices it does not own.

ValidatingAdmissionPolicy · 2 bundles
ModerateContainers · Kubernetes

Sets a Custom SELinux User

container-selinux-user

A custom SELinux user label replaces the confined context the runtime assigns to the container, granting a policy domain with transitions and file access the sandbox was never meant to allow.

ValidatingAdmissionPolicy · 2 bundles
ModerateEgressFirewalls · OVN-Kubernetes

Permits Egress to 0.0.0.0/0

egressfirewall-allow-all

An Allow entry for 0.0.0.0/0 leaves the OVN-Kubernetes egress firewall with no restriction at all, so any pod in the namespace can open connections to arbitrary internet hosts for command-and-control and data theft.

ValidatingAdmissionPolicy · 1 bundle
ModerateEgressNetworkPolicies · OpenShift

Permits Egress to 0.0.0.0/0

egressnetworkpolicy-allow-all

An Allow entry for 0.0.0.0/0 makes the namespace OpenShift SDN egress firewall permit every pod in it to reach any off-cluster address, so a compromised workload can stage tooling and exfiltrate data freely.

ValidatingAdmissionPolicy · 1 bundle
ModerateEphemeralContainers · Kubernetes

Runs With an Unconfined AppArmor Profile

ephemeralcontainer-apparmor-profile

An Unconfined AppArmor profile strips the mandatory access controls over file, capability and mount operations in the ephemeral container, usually one attached with kubectl debug, widening what a compromised process can reach on the host.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Adds a Capability Outside the Baseline Set

ephemeralcontainer-capabilities-add

Linux capabilities beyond the baseline set, such as SYS_ADMIN, SYS_MODULE, SYS_PTRACE or NET_RAW, hand an ephemeral debug container kernel level privileges it can use to mount filesystems, load modules and break out onto the node.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Adds a Capability Other Than NET_BIND_SERVICE

ephemeralcontainer-capabilities-add-netbindservice

Added capabilities other than NET_BIND_SERVICE give an ephemeral debug container kernel privileges such as raw socket access, process tracing and filesystem mounting, extending its reach past its namespace onto the node.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Retains Default Linux Capabilities

ephemeralcontainer-capabilities-drop-all

An ephemeral debug container that never drops ALL keeps the default runtime capability set, so code execution inside it inherits DAC_OVERRIDE, SETUID and NET_RAW for bypassing file permissions, regaining root and spoofing traffic.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Binds a hostPort on the Node

ephemeralcontainer-hostports

A hostPort binds the ephemeral container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Runs an Image Not Pinned to a Digest

ephemeralcontainer-image-digest

An image reference without a digest resolves through a mutable tag, so registry content can be replaced between pulls and an ephemeral debug container attached with kubectl debug runs attacker-supplied code inside a live pod.

ValidatingAdmissionPolicy · 1 bundle
ModerateEphemeralContainers · Kubernetes

Runs an Image Tagged latest

ephemeralcontainer-image-tag

Untagged and latest references float to whatever was pushed to the registry most recently, so an ephemeral debug container attached with kubectl debug can pull unreviewed or poisoned code into a live pod.

ValidatingAdmissionPolicy · 1 bundle
ModerateEphemeralContainers · Kubernetes

Runs With a Writable Root Filesystem

ephemeralcontainer-read-only-root-filesystem

A writable ephemeral container root filesystem lets an intruder drop tooling, overwrite application binaries, and rewrite configuration in place, leaving a foothold in the running pod that nothing in the image would reveal.

ValidatingAdmissionPolicy · 1 bundle
ModerateEphemeralContainers · Kubernetes

Runs With the Root Group (GID 0)

ephemeralcontainer-run-as-group

An ephemeral debug container running with GID 0 places its processes in the root group, which owns or can write many files in images and mounted host volumes, widening what a compromised process reaches.

ValidatingAdmissionPolicy · 1 bundle
ModerateEphemeralContainers · Kubernetes

May Run as Root

ephemeralcontainer-run-as-nonroot

With runAsNonRoot unset, the kubelet never rejects an image whose user is UID 0, so the ephemeral debug container silently runs as root and any compromise gains root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Runs as Root (UID 0)

ephemeralcontainer-run-as-user

Running an ephemeral debug container as UID 0 gives every process the in-container root identity, so writable host mounts, setuid binaries and isolation weaknesses become exploitable with root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Runs With an Unconfined Seccomp Profile

ephemeralcontainer-seccomp-profile

An Unconfined seccomp profile removes the syscall filter from the ephemeral container, typically attached with kubectl debug, exposing the full kernel syscall surface including the obscure calls that container escape and privilege-escalation exploits depend on.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Has No Seccomp Profile Set

ephemeralcontainer-seccomp-profile-restricted

An ephemeral container with no seccomp profile enforced at pod or ephemeral container level runs with no syscall filter, leaving the full kernel syscall surface reachable for container escape and privilege escalation.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Sets a Custom SELinux Role

ephemeralcontainer-selinux-role

A custom SELinux role label lets the ephemeral container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Sets a Non-Standard SELinux Type

ephemeralcontainer-selinux-type

An SELinux type outside the container domains, such as spc_t or unconfined_t, drops the kernel confinement that stops an ephemeral container process from reading host files and reaching devices it does not own.

ValidatingAdmissionPolicy · 2 bundles
ModerateEphemeralContainers · Kubernetes

Sets a Custom SELinux User

ephemeralcontainer-selinux-user

A custom SELinux user label replaces the confined context the runtime assigns to the ephemeral container, granting a policy domain with transitions and file access the sandbox was never meant to allow.

ValidatingAdmissionPolicy · 2 bundles
ModerateGlobalNetworkPolicies · Calico

Permits Egress to Any Destination (Calico)

globalnetworkpolicy-calico-egress-cidr

A cluster-wide Allow to 0.0.0.0/0 or ::/0 gives every selected endpoint unrestricted outbound reach, the channel a compromised workload uses to contact command-and-control hosts, pull further tooling and exfiltrate data.

ValidatingAdmissionPolicy · 1 bundle
ModerateIngresses · Kubernetes

Uses a Raw Controller Snippet Annotation

ingress-configuration-snippets

Snippet and router-override annotations are folded straight into the shared ingress controller configuration, so anyone able to create an Ingress can hijack hosts from other namespaces, strip authentication, or run code inside the controller.

ValidatingAdmissionPolicy · 1 bundle
ModerateIngresses · Kubernetes

Has Hosts Not Covered by Its TLS Configuration

ingress-tls-hosts

A routed host missing from every TLS block is served over cleartext HTTP or with a default certificate that does not match it, exposing session cookies and credentials to anyone on the network path.

ValidatingAdmissionPolicy · 1 bundle
ModerateInitContainers · Kubernetes

Runs With an Unconfined AppArmor Profile

initcontainer-apparmor-profile

An Unconfined AppArmor profile strips the mandatory access controls over file, capability and mount operations in the init container, widening what a compromised process can reach on the host.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Adds a Capability Outside the Baseline Set

initcontainer-capabilities-add

Linux capabilities beyond the baseline set, such as SYS_ADMIN, SYS_MODULE, SYS_PTRACE or NET_RAW, hand an init container kernel level privileges it can use to mount filesystems, load modules and break out onto the node.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Adds a Capability Other Than NET_BIND_SERVICE

initcontainer-capabilities-add-netbindservice

Added capabilities other than NET_BIND_SERVICE give an init container kernel privileges such as raw socket access, process tracing and filesystem mounting, extending its reach past its namespace onto the node.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Retains Default Linux Capabilities

initcontainer-capabilities-drop-all

An init container that never drops ALL keeps the default runtime capability set, so code execution inside it inherits DAC_OVERRIDE, SETUID and NET_RAW for bypassing file permissions, regaining root and spoofing traffic.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Binds a hostPort on the Node

initcontainer-hostports

A hostPort binds the init container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Runs an Image Not Pinned to a Digest

initcontainer-image-digest

An image reference without a digest resolves through a mutable tag, so registry content can be replaced between pulls and the init container silently starts running attacker-supplied code on the next restart or reschedule.

ValidatingAdmissionPolicy · 1 bundle
ModerateInitContainers · Kubernetes

Runs an Image Tagged latest

initcontainer-image-tag

Untagged and latest references float to whatever was pushed to the registry most recently, so a restart or reschedule can pull unreviewed or poisoned code into the init container without any spec change.

ValidatingAdmissionPolicy · 1 bundle
ModerateInitContainers · Kubernetes

Runs With a Writable Root Filesystem

initcontainer-read-only-root-filesystem

A writable init container root filesystem lets an intruder drop tooling, overwrite application binaries, and rewrite configuration in place, leaving a foothold in the running pod that nothing in the image would reveal.

ValidatingAdmissionPolicy · 1 bundle
ModerateInitContainers · Kubernetes

Runs With the Root Group (GID 0)

initcontainer-run-as-group

An init container running with GID 0 places its processes in the root group, which owns or can write many files in images and mounted host volumes, widening what a compromised process reaches.

ValidatingAdmissionPolicy · 1 bundle
ModerateInitContainers · Kubernetes

May Run as Root

initcontainer-run-as-nonroot

With runAsNonRoot unset, the kubelet never rejects an image whose user is UID 0, so the init container silently runs as root and any compromise gains root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Runs as Root (UID 0)

initcontainer-run-as-user

Running an init container as UID 0 gives every process the in-container root identity, so writable host mounts, setuid binaries and isolation weaknesses become exploitable with root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Runs With an Unconfined Seccomp Profile

initcontainer-seccomp-profile

An Unconfined seccomp profile removes the syscall filter from the init container, exposing the full kernel syscall surface including the obscure calls that container escape and privilege-escalation exploits depend on.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Has No Seccomp Profile Set

initcontainer-seccomp-profile-restricted

An init container with no seccomp profile enforced at pod or init container level runs with no syscall filter, leaving the full kernel syscall surface reachable for container escape and privilege escalation.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Sets a Custom SELinux Role

initcontainer-selinux-role

A custom SELinux role label lets the init container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Sets a Non-Standard SELinux Type

initcontainer-selinux-type

An SELinux type outside the container domains, such as spc_t or unconfined_t, drops the kernel confinement that stops an init container process from reading host files and reaching devices it does not own.

ValidatingAdmissionPolicy · 2 bundles
ModerateInitContainers · Kubernetes

Sets a Custom SELinux User

initcontainer-selinux-user

A custom SELinux user label replaces the confined context the runtime assigns to the init container, granting a policy domain with transitions and file access the sandbox was never meant to allow.

ValidatingAdmissionPolicy · 2 bundles
ModerateMutatingWebhookConfigurations · Kubernetes

Fails Open or Uses an Off-Cluster Endpoint

mutatingwebhookconfiguration-hardening

A webhook that fails open is bypassed by anyone who can make it unreachable, and an external URL endpoint sends every intercepted object off-cluster and lets whoever runs it rewrite workloads at admission time.

ValidatingAdmissionPolicy · 1 bundle
ModerateNamespaces · Kubernetes

Sets No Pod Security Standards Label

namespace-pod-security-standards

A namespace that is not held to at least the baseline Pod Security Standard lets anyone able to create pods there run privileged, host-networked or hostPath workloads and break out to the node unchallenged.

ValidatingAdmissionPolicy · 1 bundle
ModerateNetworkPolicies · Kubernetes

Allows All Ingress and Egress for All Pods

networkpolicy-allow-all

Selecting every pod with rules that name no peers and no ports unions an allow-all permission across the namespace, which cancels the effect of tighter policies and leaves lateral movement and outbound traffic unconstrained.

ValidatingAdmissionPolicy · 1 bundle
ModerateNetworkPolicies · Calico

Permits Egress to Any Destination (Calico)

networkpolicy-calico-egress-cidr

An Allow to 0.0.0.0/0 or ::/0 gives the selected endpoints unrestricted outbound reach, the channel a compromised workload uses to contact command-and-control hosts, pull further tooling and exfiltrate data.

ValidatingAdmissionPolicy · 1 bundle
ModerateNodes · Kubernetes

Lacks a Control Plane NoSchedule Taint

node-control-plane-schedulable

An untainted control-plane node accepts ordinary workloads alongside etcd and the API server, putting tenant containers on the one host where control-plane certificates and static pod manifests sit on disk.

ValidatingAdmissionPolicy · 1 bundle
ModeratePeerAuthentications · Istio

Does Not Require Mutual TLS

peerauthentication-mtls-weakened

Accepting plaintext connections lets anything that reaches the pod network talk to the service without proving a workload identity, and leaves service-to-service traffic readable and modifiable on the wire.

ValidatingAdmissionPolicy · 1 bundle
ModeratePods · Kubernetes

Sets a Non-Standard AppArmor Annotation

pod-apparmor-annotation-values

A legacy AppArmor annotation set to unconfined leaves the named container with no mandatory access control profile, so its file, capability and mount operations run unrestricted against the host kernel.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Runs With an Unconfined AppArmor Profile

pod-apparmor-profile

An Unconfined AppArmor profile at pod level strips the mandatory access controls over file, capability and mount operations from every container that inherits it, widening what a compromised process can reach on the host.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Leaves ServiceAccount Token Automounting Enabled

pod-automount-serviceaccount-token

An automounted service account token lands in every container filesystem, so any code execution or path traversal bug hands an attacker a live API credential for enumerating and acting on cluster resources.

ValidatingAdmissionPolicy · 1 bundle
ModeratePods · Kubernetes

Runs With the Root Group (GID 0)

pod-run-as-group

A pod running with GID 0 places its processes in the root group, which owns or can write many files in images and mounted host volumes, widening what a compromised process reaches.

ValidatingAdmissionPolicy · 1 bundle
ModeratePods · Kubernetes

May Run as Root

pod-run-as-nonroot

With runAsNonRoot unset, the kubelet never rejects an image whose user is UID 0, so the pod silently runs as root and any compromise gains root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Runs as Root (UID 0)

pod-run-as-user

Running a pod as UID 0 gives every process the in-container root identity, so writable host mounts, setuid binaries and isolation weaknesses become exploitable with root file ownership and the full capability set.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Runs With an Unconfined Seccomp Profile

pod-seccomp-profile

An Unconfined seccomp profile at pod level removes the syscall filter from every container inheriting it, exposing the full kernel syscall surface including the obscure calls that container escape and privilege-escalation exploits depend on.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Has No Seccomp Profile Set

pod-seccomp-profile-restricted

A pod with no seccomp profile enforced at pod level, and containers that set none either, runs with no syscall filter, leaving the full kernel syscall surface reachable for container escape and privilege escalation.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Sets a Custom SELinux Role

pod-selinux-role

A custom SELinux role label applied pod-wide lets containers transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Sets a Non-Standard SELinux Type

pod-selinux-type

An SELinux type outside the container domains, such as spc_t or unconfined_t, drops the kernel confinement that stops pod containers from reading host files and reaching devices they do not own.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Sets a Custom SELinux User

pod-selinux-user

A custom SELinux user label at pod level replaces the confined context the runtime assigns to every container, granting a policy domain with transitions and file access the sandbox was never meant to allow.

ValidatingAdmissionPolicy · 2 bundles
ModeratePods · Kubernetes

Shares a Process Namespace Between Containers

pod-share-process-namespace

A shared process namespace lets every container in the pod inspect and signal the others, reading secrets from sibling command lines and /proc environment files, so compromising one sidecar reaches them all.

ValidatingAdmissionPolicy · 1 bundle
ModeratePods · Kubernetes

Sets a Sysctl Outside the Approved List

pod-sysctls

A sysctl outside the approved list reaches kernel tunables shared with the node, letting a pod weaken host network and memory protections for every workload on that node and destabilise the kubelet itself.

ValidatingAdmissionPolicy · 2 bundles
ModeratePolicies · Kyverno

Audits Instead of Enforcing Violations

policy-kyverno-not-enforcing

A Policy left on Audit only records violations in a report, so the workloads it was written to block are still admitted into its namespace and the protection exists only as a log entry.

ValidatingAdmissionPolicy · 1 bundle
ModerateRoles · Kubernetes

Grants Write Access to PersistentVolumeClaims

role-pvc-write

Creating PersistentVolumeClaims in the namespace can bind a volume that still holds data from another workload into an attacker-controlled pod, while delete destroys the backing data and unbounded provisioning exhausts the storage quota.

ValidatingAdmissionPolicy · 1 bundle
ModerateRoleBindings · Kubernetes

Binds a Role to an Anonymous Identity

rolebinding-anonymous-subjects

Binding a role to system:anonymous hands its namespace permissions to every unauthenticated caller that reaches the API server, and catch-all names like everyone or all-users leave nobody accountable for who exercises them.

ValidatingAdmissionPolicy · 1 bundle
ModerateRoleBindings · Kubernetes

Binds a Privileged Role to the Default ServiceAccount

rolebinding-default-serviceaccount

Every pod that names no ServiceAccount runs as default, so a RoleBinding to it shares the granted namespace permissions across every unrelated workload there and one compromised container immediately gains them all.

ValidatingAdmissionPolicy · 1 bundle
ModerateRoleBindings · Kubernetes

Binds a Privileged Role to a System Group

rolebinding-system-groups

Naming system:authenticated, system:unauthenticated or system:serviceaccounts as a subject grants the role to every account in the cluster at once, so the namespace permissions extend to anyone who can reach the API server.

ValidatingAdmissionPolicy · 1 bundle
ModerateRoutes · OpenShift

Defines No TLS Termination

route-tls

A Route without a TLS section is published over plain HTTP at the router, so session cookies and credentials cross the network in cleartext and can be read or rewritten in transit.

ValidatingAdmissionPolicy · 1 bundle
ModerateServices · Kubernetes

Exposes an Admin or Metrics Port Externally

service-admin-ports

Admin, debug, metrics and management listeners are usually unauthenticated, so publishing them on a LoadBalancer or NodePort hands outside callers internal telemetry, profiling and heap dumps, and sometimes live control over the workload.

ValidatingAdmissionPolicy · 1 bundle
ModerateServices · Kubernetes

Claims Arbitrary External IP Addresses

service-external-ips

externalIPs make every node claim the listed addresses and steer matching traffic into the selected pods, so any namespace able to create a Service can hijack and man-in-the-middle traffic destined for those IPs.

ValidatingAdmissionPolicy · 1 bundle
ModerateServices · Kubernetes

Is Exposed on Every Node via NodePort

service-nodeport

A NodePort opens the same port on every node address, bypassing the ingress path with its TLS termination and authentication and leaving node-level firewalling as the only control between the workload and the wider network.

ValidatingAdmissionPolicy · 1 bundle
ModerateServiceAccounts · Kubernetes

Attaches More Than One Image Pull Secret

serviceaccount-imagepullsecrets-scope

Attaching several registry credentials to one ServiceAccount hands all of them to every pod that uses it, so one compromised workload exposes registry logins it never needed to pull its own image.

ValidatingAdmissionPolicy · 1 bundle
ModerateServiceAccounts · Kubernetes

Automounts Its Token Into Every Pod

serviceaccount-token-automount

A ServiceAccount that automounts by default puts its API token into every pod that references it, so any one compromised container yields a credential usable against the API server.

ValidatingAdmissionPolicy · 1 bundle
ModerateServiceAccounts · Kubernetes

References a Long-Lived Token Secret

serviceaccount-token-secrets

A long-lived token Secret bound to a ServiceAccount never expires and is tied to no pod lifetime, so a single leaked value grants that identity permanent API access until someone notices and rotates it.

ValidatingAdmissionPolicy · 1 bundle
ModerateValidatingWebhookConfigurations · Kubernetes

Fails Open or Uses an Off-Cluster Endpoint

validatingwebhookconfiguration-hardening

A webhook that fails open is bypassed by anyone who can make it unreachable, and an external URL endpoint sends every reviewed object off-cluster and lets whoever runs it decide what admission accepts.

ValidatingAdmissionPolicy · 1 bundle
LowConfigMaps · Kubernetes

Is Mutable at Runtime

configmap-immutability

A mutable ConfigMap can be rewritten by anyone with update access, silently changing application configuration, feature flags or trusted endpoints inside running pods with no new image and no deployment.

ValidatingAdmissionPolicy · 1 bundle
LowContainers · Kubernetes

Liveness Probe Targets an Arbitrary Host

container-livenessprobe-httpget-host

Redirecting the liveness HTTP probe to another host makes the kubelet fetch an arbitrary URL from the node, reaching metadata and node-local endpoints closed to pods, while a hung container is never restarted.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

Liveness TCP Probe Targets an Arbitrary Host

container-livenessprobe-tcpsocket-host

Pointing the liveness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while a hung container is never restarted.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

postStart Hook Targets an Arbitrary Host

container-poststart-httpget-host

A postStart HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node each time a container starts, reaching internal endpoints closed to pods and triggering side effects there.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

postStart TCP Hook Targets an Arbitrary Host

container-poststart-tcpsocket-host

Naming another host in a postStart TCP hook points container start at an off-pod address through a handler the kubelet does not support, so the hook fails and the container is killed.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

preStop Hook Targets an Arbitrary Host

container-prestop-httpget-host

A preStop HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node whenever a container shuts down, reaching internal endpoints closed to pods and triggering side effects there.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

preStop TCP Hook Targets an Arbitrary Host

container-prestop-tcpsocket-host

Naming another host in a preStop TCP hook points container shutdown at an off-pod address through a handler the kubelet does not support, so the hook fails and cleanup never runs.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

Readiness Probe Targets an Arbitrary Host

container-readinessprobe-httpget-host

Redirecting the readiness HTTP probe to another host makes the kubelet fetch an arbitrary URL from the node, reaching metadata and node-local endpoints closed to pods, while Service traffic keeps reaching an unchecked container.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

Readiness TCP Probe Targets an Arbitrary Host

container-readinessprobe-tcpsocket-host

Pointing the readiness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while Service traffic keeps reaching an unchecked container.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

Startup Probe Targets an Arbitrary Host

container-startupprobe-httpget-host

Redirecting the startup HTTP probe to another host makes the kubelet fetch an arbitrary URL from the node, reaching metadata and node-local endpoints closed to pods, and a hung container passes its startup gate.

ValidatingAdmissionPolicy · 2 bundles
LowContainers · Kubernetes

Startup TCP Probe Targets an Arbitrary Host

container-startupprobe-tcpsocket-host

Pointing the startup TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, and a hung container passes its startup gate.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

Liveness Probe Targets an Arbitrary Host

initcontainer-livenessprobe-httpget-host

Redirecting the liveness HTTP probe to another host makes the kubelet fetch an arbitrary URL from the node, reaching metadata and node-local endpoints closed to pods, while a hung init container is never restarted.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

Liveness TCP Probe Targets an Arbitrary Host

initcontainer-livenessprobe-tcpsocket-host

Pointing the liveness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while a hung init container is never restarted.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

postStart Hook Targets an Arbitrary Host

initcontainer-poststart-httpget-host

A postStart HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node each time an init container starts, reaching internal endpoints closed to pods and triggering side effects there.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

postStart TCP Hook Targets an Arbitrary Host

initcontainer-poststart-tcpsocket-host

Naming another host in a postStart TCP hook points init container start at an off-pod address through a handler the kubelet does not support, so the hook fails and the container is killed.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

preStop Hook Targets an Arbitrary Host

initcontainer-prestop-httpget-host

A preStop HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node whenever an init container shuts down, reaching internal endpoints closed to pods and triggering side effects there.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

preStop TCP Hook Targets an Arbitrary Host

initcontainer-prestop-tcpsocket-host

Naming another host in a preStop TCP hook points init container shutdown at an off-pod address through a handler the kubelet does not support, so the hook fails and cleanup never runs.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

Readiness Probe Targets an Arbitrary Host

initcontainer-readinessprobe-httpget-host

Redirecting the readiness HTTP probe to another host makes the kubelet fetch an arbitrary URL from the node, reaching metadata and node-local endpoints closed to pods, while pod readiness rests on an unchecked init container.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

Readiness TCP Probe Targets an Arbitrary Host

initcontainer-readinessprobe-tcpsocket-host

Pointing the readiness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while pod readiness rests on an unchecked init container.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

Startup Probe Targets an Arbitrary Host

initcontainer-startupprobe-httpget-host

Redirecting the startup HTTP probe to another host makes the kubelet fetch an arbitrary URL from the node, reaching metadata and node-local endpoints closed to pods, and a hung init container passes its startup gate.

ValidatingAdmissionPolicy · 2 bundles
LowInitContainers · Kubernetes

Startup TCP Probe Targets an Arbitrary Host

initcontainer-startupprobe-tcpsocket-host

Pointing the startup TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, and a hung init container passes its startup gate.

ValidatingAdmissionPolicy · 2 bundles
LowPods · Kubernetes

Uses ClusterFirstWithHostNet DNS Policy

pod-dns-policy

ClusterFirstWithHostNet pairs cluster DNS with host networking, so a workload that already bypasses pod network isolation can still resolve and reach every internal cluster service by name.

ValidatingAdmissionPolicy · 1 bundle
LowPods · Kubernetes

Sets Volume Ownership to the Root Group (GID 0)

pod-fsgroup

An fsGroup of 0 chowns every attached volume to the root group and gives pod processes root group membership, so volume contents and other root-group-owned files become writable by a compromised process.

ValidatingAdmissionPolicy · 1 bundle
LowPods · Kubernetes

Uses the Default ServiceAccount

pod-serviceaccount-name

Running under the namespace default ServiceAccount makes every workload share one identity, so any permission granted to it reaches all of them and API audit records cannot be traced back to a single pod.

ValidatingAdmissionPolicy · 1 bundle
LowPods · Kubernetes

Has No Labels Set

pod-template-labels

A pod with no labels cannot be selected by label, so NetworkPolicies and other selector-driven controls written for it never apply, and the workload runs unisolated and unattributable to any owner.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Azure Disks Without a Customer-Managed Key

storageclass-cmek-azure-disk

Without a Disk Encryption Set, disks provisioned from this class fall back to platform-managed keys that you cannot rotate, audit or revoke, so snapshots and disk copies stay readable to anyone with subscription-level access.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions GCP Disks Without a Customer-Managed Key

storageclass-cmek-gcp-pd

Without a Cloud KMS key, disks provisioned from this class fall back to Google-managed keys that you cannot rotate, audit or revoke, so snapshots and disk images stay readable to anyone with project-level access.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions OCI Volumes Without a Customer-Managed Key

storageclass-cmek-oci-block

Without a Vault master key, volumes provisioned from this class fall back to Oracle-managed keys that you cannot rotate, audit or revoke, so backups and volume clones stay readable to anyone with tenancy-level access.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Unencrypted AWS EBS Volumes

storageclass-encryption-aws-ebs

Volumes provisioned from this class land on unencrypted EBS disks, so anyone able to read the raw block storage or a snapshot copied to another account recovers the data without any Kubernetes access.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Unencrypted Ceph RBD Volumes

storageclass-encryption-ceph-rbd

Volumes provisioned from this class land on unencrypted RBD images, so anyone with access to the Ceph pool, an image snapshot or the backing OSD disks reads the data without any Kubernetes access.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Unencrypted IBM VPC Block Volumes

storageclass-encryption-ibm-vpc-block

Volumes provisioned from this class rely on provider-held keys that you cannot rotate or revoke, so the data on the underlying block storage and its snapshots stays readable outside your control.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Unencrypted Linode Volumes

storageclass-encryption-linode

Volumes provisioned from this class are stored without LUKS encryption, so data sits in plaintext on the Linode block storage backend and is readable from a detached volume, a clone or the underlying host.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Unencrypted Longhorn Volumes

storageclass-encryption-longhorn

Volumes provisioned from this class keep their replicas in plaintext on node disks, so anyone who can read a replica directory, a backup target or a removed disk recovers the data without any Kubernetes access.

ValidatingAdmissionPolicy · 1 bundle
LowStorageClasses · Kubernetes

Provisions Unencrypted Portworx Volumes

storageclass-encryption-portworx

Volumes provisioned from this class are stored unencrypted across the Portworx cluster, so anyone with access to a backing node disk, a cloud snapshot or the storage fabric reads the data without any Kubernetes access.

ValidatingAdmissionPolicy · 1 bundle
ExampleIstio

Allow GET Only

authorizationpolicy-workload-allow-get

Allow only HTTP GET requests to the api-gateway workload on port 8080.

AuthorizationPolicy
ExampleIstio

Allow Same Namespace

authorizationpolicy-workload-allow-same-namespace

Allow requests to the public workload only from the same namespace.

AuthorizationPolicy
ExampleIstio

Allow ServiceAccount

authorizationpolicy-workload-allow-serviceaccount

Allow requests to the payments workload only from the specified service account principal.

AuthorizationPolicy
ExampleIstio

Deny All Traffic

authorizationpolicy-workload-deny-all

Deny all requests to the blocked workload.

AuthorizationPolicy
ExampleKubernetes

Allow Intra-Namespace Traffic

networkpolicy-allow-traffic-inside-application-namespace

Allow all ingress and egress traffic between pods in the same namespace.

NetworkPolicy
ExampleKubernetes

Allow Egress to Cloud Metadata Service

networkpolicy-allow-traffic-to-cloud-metadata-service

Allow egress traffic to the cloud metadata service at 169.254.169.254 on ports 80 and 443.

NetworkPolicy
ExampleKubernetes

Allow Egress to Kube DNS

networkpolicy-allow-traffic-to-kube-dns

Allow DNS egress (TCP/UDP 53) to kube-dns/coredns in kube-system.

NetworkPolicy
ExampleKubernetes

Allow Egress to Kubelet

networkpolicy-allow-traffic-to-kubelet

Allow egress traffic to kubelet on port 10250 within 10.0.0.0/8.

NetworkPolicy
ExampleKubernetes

Allow Egress to Kubernetes API Server

networkpolicy-allow-traffic-to-kubernetes-api-server

Allow egress traffic to the Kubernetes API server on 10.96.0.1:6443.

NetworkPolicy
ExampleKubernetes

Allow Egress to Specific External IP

networkpolicy-allow-traffic-to-specific-external-ip

Allow egress traffic to the external IP 203.0.113.10/32.

NetworkPolicy
ExampleKubernetes

Deny All Traffic

networkpolicy-deny-any-any

Deny all ingress and egress traffic for all pods in the namespace.

NetworkPolicy
ExampleIstio

Mesh-wide mTLS Strict

peerauthentication-mesh-wide-strict

Enforce STRICT mTLS across the entire mesh.

PeerAuthentication
ExampleIstio

Namespace mTLS Permissive

peerauthentication-namespace-permissive

Allow both plaintext and mTLS traffic within the permissive namespace.

PeerAuthentication
ExampleIstio

mTLS Port Exception

peerauthentication-port-level-exception

Enforce STRICT mTLS for the api-gateway workload except disable mTLS on port 8080.

PeerAuthentication
ExampleIstio

Workload mTLS Strict

peerauthentication-workload-strict

Enforce STRICT mTLS for the payments workload.

PeerAuthentication
ExampleIstio

JWT Audience Validation

requestauthentication-workload-jwt-audience

Validate JWT issuer and required audience for the api-gateway workload.

RequestAuthentication
ExampleIstio

JWT Validation

requestauthentication-workload-jwt-validate

Validate JWTs for the public workload using the configured issuer and JWKS.

RequestAuthentication

The repository also ships a kube-apiserver audit policy. It is a single cluster-level configuration file rather than a catalogued rule, so it is not in the catalog above.

// the toolkit

manage these with kubeapt.

Downloading and applying YAML by hand works. kubeapt makes it repeatable: install a bundle, pin its version, scan a cluster for the gaps it would close, and validate before you enforce.