← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Sets a Custom SELinux Role

ephemeralcontainer-selinux-role

severityModerate resourceEphemeralContainers productKubernetes bundles2

A custom SELinux role label lets the ephemeral container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices.

Rejects unless

!has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
  !has(ec.securityContext) ||
  !has(ec.securityContext.seLinuxOptions) ||
  !has(ec.securityContext.seLinuxOptions.role) ||
  ec.securityContext.seLinuxOptions.role == ""
)

spec.ephemeralContainers[*].securityContext.seLinuxOptions.role must be undefined or an empty string ("").

Remediation

Remove the seLinuxOptions.role setting from every ephemeral container or leave it as an empty string so the runtime assigns its default container role. Field: spec.ephemeralContainers[*].securityContext.seLinuxOptions.role.

Applies to

  • pods/ephemeralcontainers · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: ephemeralcontainer-selinux-role
  annotations:
    kubeapt.io/uuid: "ede1c961-2201-4529-854b-501f2c9c2493"
    security.kubeapt.io/displayName: "Sets a Custom SELinux Role"
    security.kubeapt.io/description: "A custom SELinux role label lets the ephemeral container transition into domains outside the confined container role, weakening the mandatory access control that keeps a compromised process away from host files and devices."
    security.kubeapt.io/resource: "EphemeralContainers"
    security.kubeapt.io/severity: "Moderate"
    security.kubeapt.io/remediation: "Remove the seLinuxOptions.role setting from every ephemeral container or leave it as an empty string so the runtime assigns its default container role. Field: spec.ephemeralContainers[*].securityContext.seLinuxOptions.role."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods/ephemeralcontainers
  validations:
  - expression: |
      !has(object.spec.ephemeralContainers) || object.spec.ephemeralContainers.all(ec,
        !has(ec.securityContext) ||
        !has(ec.securityContext.seLinuxOptions) ||
        !has(ec.securityContext.seLinuxOptions.role) ||
        ec.securityContext.seLinuxOptions.role == ""
      )
    message: |
      spec.ephemeralContainers[*].securityContext.seLinuxOptions.role must be undefined or an empty string ("").

Save it as ephemeralcontainer-selinux-role.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./ephemeralcontainer-selinux-role.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name ephemeralcontainer-selinux-role -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name ephemeralcontainer-selinux-role -A