peerauthentication-mtls-weakened
Accepting plaintext connections lets anything that reaches the pod network talk to the service without proving a workload identity, and leaves service-to-service traffic readable and modifiable on the wire.
!(object.spec.?mtls.mode.orValue('') in ['DISABLE', 'PERMISSIVE']) &&
(!has(object.spec) || !has(object.spec.portLevelMtls) ||
object.spec.portLevelMtls.all(p,
!(object.spec.portLevelMtls[p].?mode.orValue('') in ['DISABLE', 'PERMISSIVE'])
)
)
Istio PeerAuthentications must not disable or weaken mTLS (mode DISABLE or PERMISSIVE).
Set the mTLS mode to STRICT at both the workload and the port level so plaintext connections are rejected. Fields: spec.mtls.mode, spec.portLevelMtls[*].mode.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: peerauthentication-mtls-weakened
annotations:
kubeapt.io/uuid: "50c7c898-22c5-4de3-b81e-d4689910780e"
security.kubeapt.io/displayName: "Does Not Require Mutual TLS"
security.kubeapt.io/description: "Accepting plaintext connections lets anything that reaches the pod network talk to the service without proving a workload identity, and leaves service-to-service traffic readable and modifiable on the wire."
security.kubeapt.io/resource: "PeerAuthentications"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Set the mTLS mode to STRICT at both the workload and the port level so plaintext connections are rejected. Fields: spec.mtls.mode, spec.portLevelMtls[*].mode."
security.kubeapt.io/product: "Istio"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- security.istio.io
apiVersions:
- v1
- v1beta1
operations:
- CREATE
- UPDATE
resources:
- peerauthentications
validations:
- expression: |
!(object.spec.?mtls.mode.orValue('') in ['DISABLE', 'PERMISSIVE']) &&
(!has(object.spec) || !has(object.spec.portLevelMtls) ||
object.spec.portLevelMtls.all(p,
!(object.spec.portLevelMtls[p].?mode.orValue('') in ['DISABLE', 'PERMISSIVE'])
)
)
message: |
Istio PeerAuthentications must not disable or weaken mTLS (mode DISABLE or PERMISSIVE).Save it as peerauthentication-mtls-weakened.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./peerauthentication-mtls-weakened.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name peerauthentication-mtls-weakened -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name peerauthentication-mtls-weakened -A