← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Permits Traffic to the world Entity

ciliumnetworkpolicy-egress-world

severityModerate resourceCiliumNetworkPolicies productCilium bundles1

The world entity covers every address outside the cluster, so a rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source.

Rejects unless

!has(object.spec) || (
  !object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
  !object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
)

CiliumNetworkPolicies must not allow ingress from or egress to the 'world' entity.

Remediation

Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities.

Applies to

  • ciliumnetworkpolicies · cilium.io/v2 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ciliumnetworkpolicy-egress-world
  annotations:
    kubeapt.io/uuid: "620d1c09-10b1-4b2e-9987-0595e30e45db"
    security.kubeapt.io/displayName: "Permits Traffic to the world Entity"
    security.kubeapt.io/description: "The world entity covers every address outside the cluster, so a rule using it hands the selected pods unrestricted internet egress for exfiltration and command-and-control, or exposes them to any off-cluster source."
    security.kubeapt.io/resource: "CiliumNetworkPolicies"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Drop world from the entity lists and match specific CIDRs, FQDNs or endpoint selectors instead. Fields: spec.egress[*].toEntities, spec.ingress[*].fromEntities."
    security.kubeapt.io/product: "Cilium"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - cilium.io
      apiVersions:
      - v2
      operations:
      - CREATE
      - UPDATE
      resources:
      - ciliumnetworkpolicies
  validations:
  - expression: |
      !has(object.spec) || (
        !object.spec.?egress.orValue([]).exists(e, e.?toEntities.orValue([]).exists(x, x == 'world')) &&
        !object.spec.?ingress.orValue([]).exists(i, i.?fromEntities.orValue([]).exists(x, x == 'world'))
      )
    message: |
      CiliumNetworkPolicies must not allow ingress from or egress to the 'world' entity.

Save it as ciliumnetworkpolicy-egress-world.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ciliumnetworkpolicy-egress-world.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ciliumnetworkpolicy-egress-world -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ciliumnetworkpolicy-egress-world -A