pod-hostpath-volumes
A hostPath volume mounts node filesystem paths into the pod, exposing kubelet credentials, container runtime sockets and other workload data, and a writable mount lets an attacker alter node files to take over the node.
!has(object.spec.volumes) || object.spec.volumes.all(v, !has(v.hostPath))
HostPath volumes are disallowed. Each spec.volumes[*].hostPath must be undefined.
Remove the hostPath volume and use an emptyDir, ConfigMap or PersistentVolumeClaim instead. Field: spec.volumes[*].hostPath.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: pod-hostpath-volumes
annotations:
kubeapt.io/uuid: "5612ded8-9174-42bf-80de-52468a236655"
security.kubeapt.io/displayName: "Mounts a hostPath Volume From the Node"
security.kubeapt.io/description: "A hostPath volume mounts node filesystem paths into the pod, exposing kubelet credentials, container runtime sockets and other workload data, and a writable mount lets an attacker alter node files to take over the node."
security.kubeapt.io/resource: "Pods"
security.kubeapt.io/severity: "Critical"
security.kubeapt.io/remediation: "Remove the hostPath volume and use an emptyDir, ConfigMap or PersistentVolumeClaim instead. Field: spec.volumes[*].hostPath."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
validations:
- expression: |
!has(object.spec.volumes) || object.spec.volumes.all(v, !has(v.hostPath))
message: |
HostPath volumes are disallowed. Each spec.volumes[*].hostPath must be undefined.Save it as pod-hostpath-volumes.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./pod-hostpath-volumes.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name pod-hostpath-volumes -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name pod-hostpath-volumes -A