pod-sysctls
A sysctl outside the approved list reaches kernel tunables shared with the node, letting a pod weaken host network and memory protections for every workload on that node and destabilise the kubelet itself.
!has(object.spec.securityContext) || !has(object.spec.securityContext.sysctls) || object.spec.securityContext.sysctls.all(s,
has(s.name) && variables.allowedSysctls.exists(a, a == s.name)
)
Only the approved sysctls are allowed in spec.securityContext.sysctls[*].name. Allowed: kernel.shm_rmid_forced, net.ipv4.ip_local_port_range, net.ipv4.ip_unprivileged_port_start, net.ipv4.tcp_syncookies, net.ipv4.ping_group_range, net.ipv4.ip_local_reserved_ports, net.ipv4.tcp_keepalive_time, net.ipv4.tcp_fin_timeout, net.ipv4.tcp_keepalive_intvl, net.ipv4.tcp_keepalive_probes.
allowedSysctls
["kernel.shm_rmid_forced",
"net.ipv4.ip_local_port_range",
"net.ipv4.ip_unprivileged_port_start",
"net.ipv4.tcp_syncookies",
"net.ipv4.ping_group_range",
"net.ipv4.ip_local_reserved_ports",
"net.ipv4.tcp_keepalive_time",
"net.ipv4.tcp_fin_timeout",
"net.ipv4.tcp_keepalive_intvl",
"net.ipv4.tcp_keepalive_probes"]
Remove the unapproved sysctl entries and keep only allowed names such as net.ipv4.ip_local_port_range, net.ipv4.tcp_syncookies or kernel.shm_rmid_forced. Field: spec.securityContext.sysctls[*].name.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: pod-sysctls
annotations:
kubeapt.io/uuid: "ef3af6c4-dc03-46bd-9f3c-7f9ac329edf2"
security.kubeapt.io/displayName: "Sets a Sysctl Outside the Approved List"
security.kubeapt.io/description: "A sysctl outside the approved list reaches kernel tunables shared with the node, letting a pod weaken host network and memory protections for every workload on that node and destabilise the kubelet itself."
security.kubeapt.io/resource: "Pods"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Remove the unapproved sysctl entries and keep only allowed names such as net.ipv4.ip_local_port_range, net.ipv4.tcp_syncookies or kernel.shm_rmid_forced. Field: spec.securityContext.sysctls[*].name."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
variables:
- name: allowedSysctls
expression: |
["kernel.shm_rmid_forced",
"net.ipv4.ip_local_port_range",
"net.ipv4.ip_unprivileged_port_start",
"net.ipv4.tcp_syncookies",
"net.ipv4.ping_group_range",
"net.ipv4.ip_local_reserved_ports",
"net.ipv4.tcp_keepalive_time",
"net.ipv4.tcp_fin_timeout",
"net.ipv4.tcp_keepalive_intvl",
"net.ipv4.tcp_keepalive_probes"]
validations:
- expression: |
!has(object.spec.securityContext) || !has(object.spec.securityContext.sysctls) || object.spec.securityContext.sysctls.all(s,
has(s.name) && variables.allowedSysctls.exists(a, a == s.name)
)
message: |
Only the approved sysctls are allowed in spec.securityContext.sysctls[*].name. Allowed: kernel.shm_rmid_forced, net.ipv4.ip_local_port_range, net.ipv4.ip_unprivileged_port_start, net.ipv4.tcp_syncookies, net.ipv4.ping_group_range, net.ipv4.ip_local_reserved_ports, net.ipv4.tcp_keepalive_time, net.ipv4.tcp_fin_timeout, net.ipv4.tcp_keepalive_intvl, net.ipv4.tcp_keepalive_probes.Save it as pod-sysctls.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./pod-sysctls.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name pod-sysctls -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name pod-sysctls -A