clusterrole-wildcard-rules
A wildcard in apiGroups, resources or verbs hands over an entire API group, every resource type or every operation on them across the cluster, and silently widens to each CRD installed later.
!has(object.rules) || object.rules.all(r,
!((has(r.apiGroups) && r.apiGroups.exists(ag, ag == "*")) ||
(has(r.resources) && r.resources.exists(res, res == "*")) ||
(has(r.verbs) && r.verbs.exists(v, v == "*")))
)
Wildcard rules (apiGroups/resources/verbs with "*") are disallowed.
Replace each wildcard entry with the explicit API groups, resources and verbs the workload actually calls. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: clusterrole-wildcard-rules
annotations:
kubeapt.io/uuid: "2bb2fe04-7616-4f5a-a873-b27f86a9800d"
security.kubeapt.io/displayName: "Uses Wildcard apiGroups, Resources or Verbs"
security.kubeapt.io/description: "A wildcard in apiGroups, resources or verbs hands over an entire API group, every resource type or every operation on them across the cluster, and silently widens to each CRD installed later."
security.kubeapt.io/resource: "ClusterRoles"
security.kubeapt.io/severity: "Critical"
security.kubeapt.io/remediation: "Replace each wildcard entry with the explicit API groups, resources and verbs the workload actually calls. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- rbac.authorization.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- clusterroles
validations:
- expression: |
!has(object.rules) || object.rules.all(r,
!((has(r.apiGroups) && r.apiGroups.exists(ag, ag == "*")) ||
(has(r.resources) && r.resources.exists(res, res == "*")) ||
(has(r.verbs) && r.verbs.exists(v, v == "*")))
)
message: |
Wildcard rules (apiGroups/resources/verbs with "*") are disallowed.Save it as clusterrole-wildcard-rules.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./clusterrole-wildcard-rules.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name clusterrole-wildcard-rules -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name clusterrole-wildcard-rules -A