route-tls
A Route without a TLS section is published over plain HTTP at the router, so session cookies and credentials cross the network in cleartext and can be read or rewritten in transit.
has(object.spec.tls)
OpenShift Routes must define TLS termination (spec.tls).
Add a spec.tls block using edge, reencrypt or passthrough termination so the router serves the host over HTTPS. Field: spec.tls.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: route-tls
annotations:
kubeapt.io/uuid: "b3c3431f-6cfd-4459-944c-82d2085bc5b6"
security.kubeapt.io/displayName: "Defines No TLS Termination"
security.kubeapt.io/description: "A Route without a TLS section is published over plain HTTP at the router, so session cookies and credentials cross the network in cleartext and can be read or rewritten in transit."
security.kubeapt.io/resource: "Routes"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Add a spec.tls block using edge, reencrypt or passthrough termination so the router serves the host over HTTPS. Field: spec.tls."
security.kubeapt.io/product: "OpenShift"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- route.openshift.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- routes
validations:
- expression: |
has(object.spec.tls)
message: |
OpenShift Routes must define TLS termination (spec.tls).Save it as route-tls.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./route-tls.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name route-tls -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name route-tls -A