← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Binds a hostPort on the Node

ephemeralcontainer-hostports

severityModerate resourceEphemeralContainers productKubernetes bundles2

A hostPort binds the ephemeral container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports.

Rejects unless

!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
  !has(ec.ports) ||
  ec.ports.all(p,
    !has(p.hostPort) ||
    p.hostPort == 0 ||
    variables.allowedHostPorts.exists(h, h == p.hostPort)
  )
)

Ephemeral container hostPort must be undefined, 0, or in the variables.allowedHostPorts list.

Variables

allowedHostPorts

[]

Remediation

Remove the hostPort field or set it to 0 and publish the workload through a Service instead. Field: spec.ephemeralContainers[*].ports[*].hostPort.

Applies to

  • pods/ephemeralcontainers · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ephemeralcontainer-hostports
  annotations:
    kubeapt.io/uuid: "76388b3e-0254-4b2c-b68b-901f97a3c47b"
    security.kubeapt.io/displayName: "Binds a hostPort on the Node"
    security.kubeapt.io/description: "A hostPort binds the ephemeral container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports."
    security.kubeapt.io/resource: "EphemeralContainers"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Remove the hostPort field or set it to 0 and publish the workload through a Service instead. Field: spec.ephemeralContainers[*].ports[*].hostPort."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods/ephemeralcontainers
  variables:
  - name: allowedHostPorts
    expression: |
      []
  validations:
  - expression: |
      !has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
        !has(ec.ports) ||
        ec.ports.all(p,
          !has(p.hostPort) ||
          p.hostPort == 0 ||
          variables.allowedHostPorts.exists(h, h == p.hostPort)
        )
      )
    message: |
      Ephemeral container hostPort must be undefined, 0, or in the variables.allowedHostPorts list.

Save it as ephemeralcontainer-hostports.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ephemeralcontainer-hostports.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-hostports -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ephemeralcontainer-hostports -A