container-selinux-role
A custom SELinux role label lets the container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices.
object.spec.containers.all(c,
!has(c.securityContext) ||
!has(c.securityContext.seLinuxOptions) ||
!has(c.securityContext.seLinuxOptions.role) ||
c.securityContext.seLinuxOptions.role == ""
)
spec.containers[*].securityContext.seLinuxOptions.role must be undefined or an empty string ("").
Remove the seLinuxOptions.role setting from every container or leave it as an empty string so the runtime assigns its default container role. Field: spec.containers[*].securityContext.seLinuxOptions.role.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: container-selinux-role
annotations:
kubeapt.io/uuid: "dbc328e1-5d2c-4b45-93f6-d490ad81f01e"
security.kubeapt.io/displayName: "Sets a Custom SELinux Role"
security.kubeapt.io/description: "A custom SELinux role label lets the container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices."
security.kubeapt.io/resource: "Containers"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Remove the seLinuxOptions.role setting from every container or leave it as an empty string so the runtime assigns its default container role. Field: spec.containers[*].securityContext.seLinuxOptions.role."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
validations:
- expression: |
object.spec.containers.all(c,
!has(c.securityContext) ||
!has(c.securityContext.seLinuxOptions) ||
!has(c.securityContext.seLinuxOptions.role) ||
c.securityContext.seLinuxOptions.role == ""
)
message: |
spec.containers[*].securityContext.seLinuxOptions.role must be undefined or an empty string ("").Save it as container-selinux-role.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./container-selinux-role.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name container-selinux-role -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name container-selinux-role -A