← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Runs an Image Tagged latest

ephemeralcontainer-image-tag

severityModerate resourceEphemeralContainers productKubernetes bundles1

Untagged and latest references float to whatever was pushed to the registry most recently, so an ephemeral debug container attached with kubectl debug can pull unreviewed or poisoned code into a live pod.

Rejects unless

!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
  ec.image.matches(".*@sha256:[0-9A-Fa-f]{64}") ||
  (
    ec.image.lastIndexOf(":") > ec.image.lastIndexOf("/") &&
    !ec.image.lowerAscii().endsWith(":latest")
  )
)

spec.ephemeralContainers[*].image must use an immutable digest or a non-latest tag.

Remediation

Pin the image to a specific released version tag or to an immutable @sha256 digest instead of latest or a bare repository name. Field: spec.ephemeralContainers[*].image.

Applies to

  • pods/ephemeralcontainers · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ephemeralcontainer-image-tag
  annotations:
    kubeapt.io/uuid: "c0e761a5-a977-4da6-89df-27b8b782e5ea"
    security.kubeapt.io/displayName: "Runs an Image Tagged latest"
    security.kubeapt.io/description: "Untagged and latest references float to whatever was pushed to the registry most recently, so an ephemeral debug container attached with kubectl debug can pull unreviewed or poisoned code into a live pod."
    security.kubeapt.io/resource: "EphemeralContainers"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Pin the image to a specific released version tag or to an immutable @sha256 digest instead of latest or a bare repository name. Field: spec.ephemeralContainers[*].image."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods/ephemeralcontainers
  validations:
  - expression: |
      !has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
        ec.image.matches(".*@sha256:[0-9A-Fa-f]{64}") ||
        (
          ec.image.lastIndexOf(":") > ec.image.lastIndexOf("/") &&
          !ec.image.lowerAscii().endsWith(":latest")
        )
      )
    message: |
      spec.ephemeralContainers[*].image must use an immutable digest or a non-latest tag.

Save it as ephemeralcontainer-image-tag.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ephemeralcontainer-image-tag.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-image-tag -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ephemeralcontainer-image-tag -A