ingress-configuration-snippets
Snippet and router-override annotations are folded straight into the shared ingress controller configuration, so anyone able to create an Ingress can hijack hosts from other namespaces, strip authentication, or run code inside the controller.
!has(object.metadata.annotations) || (
!object.metadata.annotations.exists(k, v, k in [
"nginx.ingress.kubernetes.io/configuration-snippet",
"nginx.ingress.kubernetes.io/server-snippet",
"nginx.ingress.kubernetes.io/location-snippet",
"nginx.ingress.kubernetes.io/auth-snippet",
"nginx.ingress.kubernetes.io/proxy-snippet",
"traefik.ingress.kubernetes.io/router.middlewares",
"traefik.ingress.kubernetes.io/router.tls.options",
"haproxy.org/server-snippet",
"haproxy.org/backend-config-snippet",
"haproxy.org/frontend-config-snippet"
])
)
Dangerous Ingress annotations (config/server/location/auth/proxy snippets) are disallowed except in tightly-controlled namespaces.
Delete the nginx, haproxy and traefik snippet and router-override annotations and make the routing or authentication change through supported Ingress fields or controller configuration owned by the platform team. Field: metadata.annotations.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: ingress-configuration-snippets
annotations:
kubeapt.io/uuid: "458979ee-7792-497e-9c29-df31eb75f147"
security.kubeapt.io/displayName: "Uses a Raw Controller Snippet Annotation"
security.kubeapt.io/description: "Snippet and router-override annotations are folded straight into the shared ingress controller configuration, so anyone able to create an Ingress can hijack hosts from other namespaces, strip authentication, or run code inside the controller."
security.kubeapt.io/resource: "Ingresses"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Delete the nginx, haproxy and traefik snippet and router-override annotations and make the routing or authentication change through supported Ingress fields or controller configuration owned by the platform team. Field: metadata.annotations."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- networking.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- ingresses
validations:
- expression: |
!has(object.metadata.annotations) || (
!object.metadata.annotations.exists(k, v, k in [
"nginx.ingress.kubernetes.io/configuration-snippet",
"nginx.ingress.kubernetes.io/server-snippet",
"nginx.ingress.kubernetes.io/location-snippet",
"nginx.ingress.kubernetes.io/auth-snippet",
"nginx.ingress.kubernetes.io/proxy-snippet",
"traefik.ingress.kubernetes.io/router.middlewares",
"traefik.ingress.kubernetes.io/router.tls.options",
"haproxy.org/server-snippet",
"haproxy.org/backend-config-snippet",
"haproxy.org/frontend-config-snippet"
])
)
message: |
Dangerous Ingress annotations (config/server/location/auth/proxy snippets) are disallowed except in tightly-controlled namespaces.Save it as ingress-configuration-snippets.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./ingress-configuration-snippets.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name ingress-configuration-snippets -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name ingress-configuration-snippets -A