← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Allows Traffic Across All Namespaces

baselineadminnetworkpolicy-allow-all

severityModerate resourceBaselineAdminNetworkPolicies productKubernetes bundles1

An Allow rule with an empty namespaces selector matches every namespace in the cluster, so any traffic that no NetworkPolicy or AdminNetworkPolicy decides falls back to being permitted rather than dropped.

Rejects unless

!has(object.spec) || (
  !object.spec.?ingress.orValue([]).exists(r,
    r.?action.orValue('') == 'Allow' &&
    r.?from.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
  ) &&
  !object.spec.?egress.orValue([]).exists(r,
    r.?action.orValue('') == 'Allow' &&
    r.?to.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
  )
)

BaselineAdminNetworkPolicies must not Allow traffic to/from all namespaces (empty namespace selector).

Remediation

Give each Allow rule a namespaces selector that names the specific namespaces it should cover instead of an empty match-all selector. Fields: spec.ingress[*].from[*].namespaces, spec.egress[*].to[*].namespaces.

Applies to

  • baselineadminnetworkpolicies · policy.networking.k8s.io/v1alpha1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: baselineadminnetworkpolicy-allow-all
  annotations:
    kubeapt.io/uuid: "6226d56c-42b0-412c-a8b0-39a131744b9a"
    security.kubeapt.io/displayName: "Allows Traffic Across All Namespaces"
    security.kubeapt.io/description: "An Allow rule with an empty namespaces selector matches every namespace in the cluster, so any traffic that no NetworkPolicy or AdminNetworkPolicy decides falls back to being permitted rather than dropped."
    security.kubeapt.io/resource: "BaselineAdminNetworkPolicies"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Give each Allow rule a namespaces selector that names the specific namespaces it should cover instead of an empty match-all selector. Fields: spec.ingress[*].from[*].namespaces, spec.egress[*].to[*].namespaces."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - policy.networking.k8s.io
      apiVersions:
      - v1alpha1
      operations:
      - CREATE
      - UPDATE
      resources:
      - baselineadminnetworkpolicies
  validations:
  - expression: |
      !has(object.spec) || (
        !object.spec.?ingress.orValue([]).exists(r,
          r.?action.orValue('') == 'Allow' &&
          r.?from.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
        ) &&
        !object.spec.?egress.orValue([]).exists(r,
          r.?action.orValue('') == 'Allow' &&
          r.?to.orValue([]).exists(p, has(p.namespaces) && size(p.namespaces) == 0)
        )
      )
    message: |
      BaselineAdminNetworkPolicies must not Allow traffic to/from all namespaces (empty namespace selector).

Save it as baselineadminnetworkpolicy-allow-all.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./baselineadminnetworkpolicy-allow-all.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name baselineadminnetworkpolicy-allow-all -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name baselineadminnetworkpolicy-allow-all -A