ephemeralcontainer-image-tag
Untagged and latest references float to whatever was pushed to the registry most recently, so an ephemeral debug container attached with kubectl debug can pull unreviewed or poisoned code into a live pod.
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
ec.image.matches(".*@sha256:[0-9A-Fa-f]{64}") ||
(
ec.image.lastIndexOf(":") > ec.image.lastIndexOf("/") &&
!ec.image.lowerAscii().endsWith(":latest")
)
)
spec.ephemeralContainers[*].image must use an immutable digest or a non-latest tag.
Pin the image to a specific released version tag or to an immutable @sha256 digest instead of latest or a bare repository name. Field: spec.ephemeralContainers[*].image.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: ephemeralcontainer-image-tag
annotations:
kubeapt.io/uuid: "c0e761a5-a977-4da6-89df-27b8b782e5ea"
security.kubeapt.io/displayName: "Runs an Image Tagged latest"
security.kubeapt.io/description: "Untagged and latest references float to whatever was pushed to the registry most recently, so an ephemeral debug container attached with kubectl debug can pull unreviewed or poisoned code into a live pod."
security.kubeapt.io/resource: "EphemeralContainers"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Pin the image to a specific released version tag or to an immutable @sha256 digest instead of latest or a bare repository name. Field: spec.ephemeralContainers[*].image."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods/ephemeralcontainers
validations:
- expression: |
!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
ec.image.matches(".*@sha256:[0-9A-Fa-f]{64}") ||
(
ec.image.lastIndexOf(":") > ec.image.lastIndexOf("/") &&
!ec.image.lowerAscii().endsWith(":latest")
)
)
message: |
spec.ephemeralContainers[*].image must use an immutable digest or a non-latest tag.Save it as ephemeralcontainer-image-tag.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./ephemeralcontainer-image-tag.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-image-tag -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name ephemeralcontainer-image-tag -A