clusterrole-nodes-proxy-get
Get on the node proxy subresource forwards requests straight to the kubelet API, exposing the pod inventory, container logs and runtime detail of every workload scheduled on that node.
!has(object.rules) || object.rules.all(r,
!(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, res == "nodes/proxy") &&
r.verbs.exists(v, v == "get")
)
)
ClusterRoles must not grant get access to nodes/proxy.
Remove the get verb for nodes/proxy in the core API group and read workload data through the pods and pods/log APIs instead. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: clusterrole-nodes-proxy-get
annotations:
kubeapt.io/uuid: "83c49431-dc09-4340-9d03-fe99349e6d3a"
security.kubeapt.io/displayName: "Grants get on nodes/proxy (Kubelet API)"
security.kubeapt.io/description: "Get on the node proxy subresource forwards requests straight to the kubelet API, exposing the pod inventory, container logs and runtime detail of every workload scheduled on that node."
security.kubeapt.io/resource: "ClusterRoles"
security.kubeapt.io/severity: "High"
security.kubeapt.io/remediation: "Remove the get verb for nodes/proxy in the core API group and read workload data through the pods and pods/log APIs instead. Fields: rules[*].apiGroups, rules[*].resources, rules[*].verbs."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- rbac.authorization.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- clusterroles
validations:
- expression: |
!has(object.rules) || object.rules.all(r,
!(has(r.apiGroups) && has(r.resources) && has(r.verbs) &&
r.apiGroups.exists(ag, ag == "") &&
r.resources.exists(res, res == "nodes/proxy") &&
r.verbs.exists(v, v == "get")
)
)
message: |
ClusterRoles must not grant get access to nodes/proxy.Save it as clusterrole-nodes-proxy-get.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./clusterrole-nodes-proxy-get.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name clusterrole-nodes-proxy-get -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name clusterrole-nodes-proxy-get -A