← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Uses a Raw Controller Snippet Annotation

ingress-configuration-snippets

severityModerate resourceIngresses productKubernetes bundles1

Snippet and router-override annotations are folded straight into the shared ingress controller configuration, so anyone able to create an Ingress can hijack hosts from other namespaces, strip authentication, or run code inside the controller.

Rejects unless

!has(object.metadata.annotations) || (
  !object.metadata.annotations.exists(k, v, k in [
    "nginx.ingress.kubernetes.io/configuration-snippet",
    "nginx.ingress.kubernetes.io/server-snippet",
    "nginx.ingress.kubernetes.io/location-snippet",
    "nginx.ingress.kubernetes.io/auth-snippet",
    "nginx.ingress.kubernetes.io/proxy-snippet",
    "traefik.ingress.kubernetes.io/router.middlewares",
    "traefik.ingress.kubernetes.io/router.tls.options",
    "haproxy.org/server-snippet",
    "haproxy.org/backend-config-snippet",
    "haproxy.org/frontend-config-snippet"
  ])
)

Dangerous Ingress annotations (config/server/location/auth/proxy snippets) are disallowed except in tightly-controlled namespaces.

Remediation

Delete the nginx, haproxy and traefik snippet and router-override annotations and make the routing or authentication change through supported Ingress fields or controller configuration owned by the platform team. Field: metadata.annotations.

Applies to

  • ingresses · networking.k8s.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ingress-configuration-snippets
  annotations:
    kubeapt.io/uuid: "458979ee-7792-497e-9c29-df31eb75f147"
    security.kubeapt.io/displayName: "Uses a Raw Controller Snippet Annotation"
    security.kubeapt.io/description: "Snippet and router-override annotations are folded straight into the shared ingress controller configuration, so anyone able to create an Ingress can hijack hosts from other namespaces, strip authentication, or run code inside the controller."
    security.kubeapt.io/resource: "Ingresses"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Delete the nginx, haproxy and traefik snippet and router-override annotations and make the routing or authentication change through supported Ingress fields or controller configuration owned by the platform team. Field: metadata.annotations."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - networking.k8s.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - ingresses
  validations:
  - expression: |
      !has(object.metadata.annotations) || (
        !object.metadata.annotations.exists(k, v, k in [
          "nginx.ingress.kubernetes.io/configuration-snippet",
          "nginx.ingress.kubernetes.io/server-snippet",
          "nginx.ingress.kubernetes.io/location-snippet",
          "nginx.ingress.kubernetes.io/auth-snippet",
          "nginx.ingress.kubernetes.io/proxy-snippet",
          "traefik.ingress.kubernetes.io/router.middlewares",
          "traefik.ingress.kubernetes.io/router.tls.options",
          "haproxy.org/server-snippet",
          "haproxy.org/backend-config-snippet",
          "haproxy.org/frontend-config-snippet"
        ])
      )
    message: |
      Dangerous Ingress annotations (config/server/location/auth/proxy snippets) are disallowed except in tightly-controlled namespaces.

Save it as ingress-configuration-snippets.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ingress-configuration-snippets.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ingress-configuration-snippets -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ingress-configuration-snippets -A