container-readinessprobe-tcpsocket-host
Pointing the readiness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while Service traffic keeps reaching an unchecked container.
object.spec.containers.all(c,
!has(c.readinessProbe) ||
!has(c.readinessProbe.tcpSocket) ||
!has(c.readinessProbe.tcpSocket.host) ||
c.readinessProbe.tcpSocket.host == ""
)
spec.containers[*].readinessProbe.tcpSocket.host must be undefined or empty ("").
Remove the host field so the probe targets the pod IP, or set it to an empty string. Field: spec.containers[*].readinessProbe.tcpSocket.host.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: container-readinessprobe-tcpsocket-host
annotations:
kubeapt.io/uuid: "15864541-e1ff-4369-b8c5-785ced7de8ce"
security.kubeapt.io/displayName: "Readiness TCP Probe Targets an Arbitrary Host"
security.kubeapt.io/description: "Pointing the readiness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while Service traffic keeps reaching an unchecked container."
security.kubeapt.io/resource: "Containers"
security.kubeapt.io/severity: "Low"
security.kubeapt.io/remediation: "Remove the host field so the probe targets the pod IP, or set it to an empty string. Field: spec.containers[*].readinessProbe.tcpSocket.host."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
validations:
- expression: |
object.spec.containers.all(c,
!has(c.readinessProbe) ||
!has(c.readinessProbe.tcpSocket) ||
!has(c.readinessProbe.tcpSocket.host) ||
c.readinessProbe.tcpSocket.host == ""
)
message: |
spec.containers[*].readinessProbe.tcpSocket.host must be undefined or empty ("").Save it as container-readinessprobe-tcpsocket-host.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./container-readinessprobe-tcpsocket-host.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name container-readinessprobe-tcpsocket-host -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name container-readinessprobe-tcpsocket-host -A