← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Liveness TCP Probe Targets an Arbitrary Host

container-livenessprobe-tcpsocket-host

severityLow resourceContainers productKubernetes bundles2

Pointing the liveness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while a hung container is never restarted.

Rejects unless

object.spec.containers.all(c,
  !has(c.livenessProbe) ||
  !has(c.livenessProbe.tcpSocket) ||
  !has(c.livenessProbe.tcpSocket.host) ||
  c.livenessProbe.tcpSocket.host == ""
)

spec.containers[*].livenessProbe.tcpSocket.host must be undefined or empty ("").

Remediation

Remove the host field so the probe targets the pod IP, or set it to an empty string. Field: spec.containers[*].livenessProbe.tcpSocket.host.

Applies to

  • pods · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: container-livenessprobe-tcpsocket-host
  annotations:
    kubeapt.io/uuid: "407ba943-2a0f-471c-8bf7-5088e408d4d7"
    security.kubeapt.io/displayName: "Liveness TCP Probe Targets an Arbitrary Host"
    security.kubeapt.io/description: "Pointing the liveness TCP probe at another host makes the kubelet open connections from the node to an arbitrary address, probing endpoints closed to pods, while a hung container is never restarted."
    security.kubeapt.io/resource: "Containers"
    security.kubeapt.io/severity: "Low"
    security.kubeapt.io/remediation: "Remove the host field so the probe targets the pod IP, or set it to an empty string. Field: spec.containers[*].livenessProbe.tcpSocket.host."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods
  validations:
  - expression: |
      object.spec.containers.all(c,
        !has(c.livenessProbe) ||
        !has(c.livenessProbe.tcpSocket) ||
        !has(c.livenessProbe.tcpSocket.host) ||
        c.livenessProbe.tcpSocket.host == ""
      )
    message: |
      spec.containers[*].livenessProbe.tcpSocket.host must be undefined or empty ("").

Save it as container-livenessprobe-tcpsocket-host.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./container-livenessprobe-tcpsocket-host.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name container-livenessprobe-tcpsocket-host -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name container-livenessprobe-tcpsocket-host -A