storageclass-encryption-ceph-rbd
Volumes provisioned from this class land on unencrypted RBD images, so anyone with access to the Ceph pool, an image snapshot or the backing OSD disks reads the data without any Kubernetes access.
object.provisioner != 'rbd.csi.ceph.com' ||
(has(object.parameters) && 'encrypted' in object.parameters &&
object.parameters['encrypted'] == 'true')
Ceph RBD StorageClasses must enable at-rest encryption (parameters.encrypted: "true").
Set parameters.encrypted to true on rbd.csi.ceph.com StorageClasses and point parameters.encryptionKMSID at the configured KMS entry. Field: parameters.encrypted.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: storageclass-encryption-ceph-rbd
annotations:
kubeapt.io/uuid: "f9881fc5-db3d-4cd5-9788-f6529f0f853e"
security.kubeapt.io/displayName: "Provisions Unencrypted Ceph RBD Volumes"
security.kubeapt.io/description: "Volumes provisioned from this class land on unencrypted RBD images, so anyone with access to the Ceph pool, an image snapshot or the backing OSD disks reads the data without any Kubernetes access."
security.kubeapt.io/resource: "StorageClasses"
security.kubeapt.io/severity: "Low"
security.kubeapt.io/remediation: "Set parameters.encrypted to true on rbd.csi.ceph.com StorageClasses and point parameters.encryptionKMSID at the configured KMS entry. Field: parameters.encrypted."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- storage.k8s.io
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- storageclasses
validations:
- expression: |
object.provisioner != 'rbd.csi.ceph.com' ||
(has(object.parameters) && 'encrypted' in object.parameters &&
object.parameters['encrypted'] == 'true')
message: |
Ceph RBD StorageClasses must enable at-rest encryption (parameters.encrypted: "true").Save it as storageclass-encryption-ceph-rbd.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./storageclass-encryption-ceph-rbd.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name storageclass-encryption-ceph-rbd -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name storageclass-encryption-ceph-rbd -A