configmap-immutability
A mutable ConfigMap can be rewritten by anyone with update access, silently changing application configuration, feature flags or trusted endpoints inside running pods with no new image and no deployment.
has(object.immutable) && object.immutable == true
immutable must be set to true to prevent runtime tampering.
Set immutable to true on the ConfigMap and ship changes by creating a new versioned ConfigMap that the workload is repointed to. Field: immutable.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: configmap-immutability
annotations:
kubeapt.io/uuid: "347134fc-2e95-4b42-93bc-d9098b018a6b"
security.kubeapt.io/displayName: "Is Mutable at Runtime"
security.kubeapt.io/description: "A mutable ConfigMap can be rewritten by anyone with update access, silently changing application configuration, feature flags or trusted endpoints inside running pods with no new image and no deployment."
security.kubeapt.io/resource: "ConfigMaps"
security.kubeapt.io/severity: "Low"
security.kubeapt.io/remediation: "Set immutable to true on the ConfigMap and ship changes by creating a new versioned ConfigMap that the workload is repointed to. Field: immutable."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- configmaps
validations:
- expression: |
has(object.immutable) && object.immutable == true
message: |
immutable must be set to true to prevent runtime tampering.Save it as configmap-immutability.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./configmap-immutability.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name configmap-immutability -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name configmap-immutability -A