ephemeralcontainer-hostports
A hostPort binds the ephemeral container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports.
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
!has(ec.ports) ||
ec.ports.all(p,
!has(p.hostPort) ||
p.hostPort == 0 ||
variables.allowedHostPorts.exists(h, h == p.hostPort)
)
)
Ephemeral container hostPort must be undefined, 0, or in the variables.allowedHostPorts list.
allowedHostPorts
[]
Remove the hostPort field or set it to 0 and publish the workload through a Service instead. Field: spec.ephemeralContainers[*].ports[*].hostPort.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: ephemeralcontainer-hostports
annotations:
kubeapt.io/uuid: "76388b3e-0254-4b2c-b68b-901f97a3c47b"
security.kubeapt.io/displayName: "Binds a hostPort on the Node"
security.kubeapt.io/description: "A hostPort binds the ephemeral container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports."
security.kubeapt.io/resource: "EphemeralContainers"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Remove the hostPort field or set it to 0 and publish the workload through a Service instead. Field: spec.ephemeralContainers[*].ports[*].hostPort."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods/ephemeralcontainers
variables:
- name: allowedHostPorts
expression: |
[]
validations:
- expression: |
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
!has(ec.ports) ||
ec.ports.all(p,
!has(p.hostPort) ||
p.hostPort == 0 ||
variables.allowedHostPorts.exists(h, h == p.hostPort)
)
)
message: |
Ephemeral container hostPort must be undefined, 0, or in the variables.allowedHostPorts list.Save it as ephemeralcontainer-hostports.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./ephemeralcontainer-hostports.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-hostports -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name ephemeralcontainer-hostports -A