clusterrole-pod-exec-create
Pod write lets the holder run arbitrary images with any service account token in the cluster mounted, while exec, attach, port-forward and ephemeral container access opens a shell into running workloads and their credentials.
!has(object.rules) || object.rules.all(r,
!(
(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, res == "pods") &&
r.verbs.exists(v, variables.podWriteVerbs.exists(pv, pv == v)))
||
(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, variables.execResources.exists(er, er == res)) &&
r.verbs.exists(v, v == "create"))
)
)
ClusterRoles must not allow pod creation/modification or exec/attach/portforward/ephemeralcontainers access.
podWriteVerbs
["create","update","patch","delete"]
execResources
["pods/exec","pods/attach","pods/portforward","pods/ephemeralcontainers"]
Remove create, update, patch and delete on pods, and the create verb on the pods/exec, pods/attach, pods/portforward and pods/ephemeralcontainers subresources. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: clusterrole-pod-exec-create
annotations:
kubeapt.io/uuid: "2c6c1af9-6e01-45bf-8d23-a17811b4dae0"
security.kubeapt.io/displayName: "Grants Pod Create and Exec Access"
security.kubeapt.io/description: "Pod write lets the holder run arbitrary images with any service account token in the cluster mounted, while exec, attach, port-forward and ephemeral container access opens a shell into running workloads and their credentials."
security.kubeapt.io/resource: "ClusterRoles"
security.kubeapt.io/severity: "Critical"
security.kubeapt.io/remediation: "Remove create, update, patch and delete on pods, and the create verb on the pods/exec, pods/attach, pods/portforward and pods/ephemeralcontainers subresources. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- rbac.authorization.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- clusterroles
variables:
- name: podWriteVerbs
expression: |
["create","update","patch","delete"]
- name: execResources
expression: |
["pods/exec","pods/attach","pods/portforward","pods/ephemeralcontainers"]
validations:
- expression: |
!has(object.rules) || object.rules.all(r,
!(
(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, res == "pods") &&
r.verbs.exists(v, variables.podWriteVerbs.exists(pv, pv == v)))
||
(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, variables.execResources.exists(er, er == res)) &&
r.verbs.exists(v, v == "create"))
)
)
message: |
ClusterRoles must not allow pod creation/modification or exec/attach/portforward/ephemeralcontainers access.Save it as clusterrole-pod-exec-create.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./clusterrole-pod-exec-create.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name clusterrole-pod-exec-create -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name clusterrole-pod-exec-create -A