← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Defines No TLS Termination

route-tls

severityModerate resourceRoutes productOpenShift bundles1

A Route without a TLS section is published over plain HTTP at the router, so session cookies and credentials cross the network in cleartext and can be read or rewritten in transit.

Rejects unless

has(object.spec.tls)

OpenShift Routes must define TLS termination (spec.tls).

Remediation

Add a spec.tls block using edge, reencrypt or passthrough termination so the router serves the host over HTTPS. Field: spec.tls.

Applies to

  • routes · route.openshift.io/v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: route-tls
  annotations:
    kubeapt.io/uuid: "b3c3431f-6cfd-4459-944c-82d2085bc5b6"
    security.kubeapt.io/displayName: "Defines No TLS Termination"
    security.kubeapt.io/description: "A Route without a TLS section is published over plain HTTP at the router, so session cookies and credentials cross the network in cleartext and can be read or rewritten in transit."
    security.kubeapt.io/resource: "Routes"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Add a spec.tls block using edge, reencrypt or passthrough termination so the router serves the host over HTTPS. Field: spec.tls."
    security.kubeapt.io/product: "OpenShift"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - route.openshift.io
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - routes
  validations:
  - expression: |
      has(object.spec.tls)
    message: |
      OpenShift Routes must define TLS termination (spec.tls).

Save it as route-tls.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./route-tls.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name route-tls -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name route-tls -A