baselineadminnetworkpolicy-allow-all
An Allow rule with an empty namespaces selector matches every namespace in the cluster, so any traffic that no NetworkPolicy or AdminNetworkPolicy decides falls back to being permitted rather than dropped.
!has(object.spec) || (
!object.spec.?ingress.orValue([]).exists(r,
r.?action.orValue('') == 'Allow' &&
r.?from.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
) &&
!object.spec.?egress.orValue([]).exists(r,
r.?action.orValue('') == 'Allow' &&
r.?to.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
)
)
BaselineAdminNetworkPolicies must not Allow traffic to/from all namespaces (empty namespace selector).
Give each Allow rule a namespaces selector that names the specific namespaces it should cover instead of an empty match-all selector. Fields: spec.ingress[*].from[*].namespaces, spec.egress[*].to[*].namespaces.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: baselineadminnetworkpolicy-allow-all
annotations:
kubeapt.io/uuid: "6226d56c-42b0-412c-a8b0-39a131744b9a"
security.kubeapt.io/displayName: "Allows Traffic Across All Namespaces"
security.kubeapt.io/description: "An Allow rule with an empty namespaces selector matches every namespace in the cluster, so any traffic that no NetworkPolicy or AdminNetworkPolicy decides falls back to being permitted rather than dropped."
security.kubeapt.io/resource: "BaselineAdminNetworkPolicies"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Give each Allow rule a namespaces selector that names the specific namespaces it should cover instead of an empty match-all selector. Fields: spec.ingress[*].from[*].namespaces, spec.egress[*].to[*].namespaces."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- policy.networking.k8s.io
apiVersions:
- v1alpha1
operations:
- CREATE
- UPDATE
resources:
- baselineadminnetworkpolicies
validations:
- expression: |
!has(object.spec) || (
!object.spec.?ingress.orValue([]).exists(r,
r.?action.orValue('') == 'Allow' &&
r.?from.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
) &&
!object.spec.?egress.orValue([]).exists(r,
r.?action.orValue('') == 'Allow' &&
r.?to.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
)
)
message: |
BaselineAdminNetworkPolicies must not Allow traffic to/from all namespaces (empty namespace selector).Save it as baselineadminnetworkpolicy-allow-all.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./baselineadminnetworkpolicy-allow-all.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name baselineadminnetworkpolicy-allow-all -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name baselineadminnetworkpolicy-allow-all -A