← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Binds a hostPort on the Node

initcontainer-hostports

severityModerate resourceInitContainers productKubernetes bundles2

A hostPort binds the init container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports.

Rejects unless

!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
  !has(ic.ports) ||
  ic.ports.all(p,
    !has(p.hostPort) ||
    p.hostPort == 0 ||
    variables.allowedHostPorts.exists(h, h == p.hostPort)
  )
)

initContainer hostPort must be undefined, 0, or in the variables.allowedHostPorts list.

Variables

allowedHostPorts

[]

Remediation

Remove the hostPort field or set it to 0 and publish the workload through a Service instead. Field: spec.initContainers[*].ports[*].hostPort.

Applies to

  • pods · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: initcontainer-hostports
  annotations:
    kubeapt.io/uuid: "ac16a8ff-1089-4e1d-a470-89958cc479ae"
    security.kubeapt.io/displayName: "Binds a hostPort on the Node"
    security.kubeapt.io/description: "A hostPort binds the init container port onto the node network interfaces, exposing it to anything that can reach the node, bypassing Service and NetworkPolicy controls and squatting on node component ports."
    security.kubeapt.io/resource: "InitContainers"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Remove the hostPort field or set it to 0 and publish the workload through a Service instead. Field: spec.initContainers[*].ports[*].hostPort."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods
  variables:
  - name: allowedHostPorts
    expression: |
      []
  validations:
  - expression: |
      !has(object.spec.initContainers) || object.spec.initContainers.all(ic,
        !has(ic.ports) ||
        ic.ports.all(p,
          !has(p.hostPort) ||
          p.hostPort == 0 ||
          variables.allowedHostPorts.exists(h, h == p.hostPort)
        )
      )
    message: |
      initContainer hostPort must be undefined, 0, or in the variables.allowedHostPorts list.

Save it as initcontainer-hostports.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./initcontainer-hostports.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name initcontainer-hostports -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name initcontainer-hostports -A