← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

postStart TCP Hook Targets an Arbitrary Host

initcontainer-poststart-tcpsocket-host

severityLow resourceInitContainers productKubernetes bundles2

Naming another host in a postStart TCP hook points init container start at an off-pod address through a handler the kubelet does not support, so the hook fails and the container is killed.

Rejects unless

!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
  !has(ic.lifecycle) ||
  !has(ic.lifecycle.postStart) ||
  !has(ic.lifecycle.postStart.tcpSocket) ||
  !has(ic.lifecycle.postStart.tcpSocket.host) ||
  ic.lifecycle.postStart.tcpSocket.host == ""
)

spec.initContainers[*].lifecycle.postStart.tcpSocket.host must be undefined or empty ("").

Remediation

Remove the host field or set it to an empty string, and prefer an exec or httpGet handler since tcpSocket hooks are unsupported. Field: spec.initContainers[*].lifecycle.postStart.tcpSocket.host.

Applies to

  • pods · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: initcontainer-poststart-tcpsocket-host
  annotations:
    kubeapt.io/uuid: "ddff5010-e03c-4791-ae99-ae1f6f9cfe24"
    security.kubeapt.io/displayName: "postStart TCP Hook Targets an Arbitrary Host"
    security.kubeapt.io/description: "Naming another host in a postStart TCP hook points init container start at an off-pod address through a handler the kubelet does not support, so the hook fails and the container is killed."
    security.kubeapt.io/resource: "InitContainers"
    security.kubeapt.io/severity: "Low"
    security.kubeapt.io/remediation: "Remove the host field or set it to an empty string, and prefer an exec or httpGet handler since tcpSocket hooks are unsupported. Field: spec.initContainers[*].lifecycle.postStart.tcpSocket.host."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods
  validations:
  - expression: |
      !has(object.spec.initContainers) || object.spec.initContainers.all(ic,
        !has(ic.lifecycle) ||
        !has(ic.lifecycle.postStart) ||
        !has(ic.lifecycle.postStart.tcpSocket) ||
        !has(ic.lifecycle.postStart.tcpSocket.host) ||
        ic.lifecycle.postStart.tcpSocket.host == ""
      )
    message: |
      spec.initContainers[*].lifecycle.postStart.tcpSocket.host must be undefined or empty ("").

Save it as initcontainer-poststart-tcpsocket-host.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./initcontainer-poststart-tcpsocket-host.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name initcontainer-poststart-tcpsocket-host -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name initcontainer-poststart-tcpsocket-host -A