← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Permits Traffic to the world Entity

ciliumclusterwidenetworkpolicy-egress-world

severityModerate resourceCiliumClusterwideNetworkPolicies productCilium bundles1

The world entity covers every address outside the cluster, so a cluster-wide rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source.

Rejects unless

!has(object.spec) || (
  !object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
  !object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
)

CiliumClusterwideNetworkPolicies must not allow ingress from or egress to the 'world' entity.

Remediation

Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities.

Applies to

  • ciliumclusterwidenetworkpolicies · cilium.io/v2 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ciliumclusterwidenetworkpolicy-egress-world
  annotations:
    kubeapt.io/uuid: "0c5ae649-347c-41d8-b00e-f606594917f8"
    security.kubeapt.io/displayName: "Permits Traffic to the world Entity"
    security.kubeapt.io/description: "The world entity covers every address outside the cluster, so a cluster-wide rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source."
    security.kubeapt.io/resource: "CiliumClusterwideNetworkPolicies"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities."
    security.kubeapt.io/product: "Cilium"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - cilium.io
      apiVersions:
      - v2
      operations:
      - CREATE
      - UPDATE
      resources:
      - ciliumclusterwidenetworkpolicies
  validations:
  - expression: |
      !has(object.spec) || (
        !object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
        !object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
      )
    message: |
      CiliumClusterwideNetworkPolicies must not allow ingress from or egress to the 'world' entity.

Save it as ciliumclusterwidenetworkpolicy-egress-world.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ciliumclusterwidenetworkpolicy-egress-world.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ciliumclusterwidenetworkpolicy-egress-world -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ciliumclusterwidenetworkpolicy-egress-world -A