persistentvolume-hostpath
A hostPath or local PersistentVolume hands pods a path on the node filesystem, so any workload that binds the claim can read or tamper with kubelet credentials and other tenants' data.
!has(object.spec.hostPath) && !has(object.spec.local)
PersistentVolumes must not be backed by a node-local hostPath or local volume.
Back the volume with a CSI or network storage source and remove the node-local source. Fields: spec.hostPath, spec.local.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: persistentvolume-hostpath
annotations:
kubeapt.io/uuid: "fbbade48-edc3-4fc9-9285-32924d2c5e4b"
security.kubeapt.io/displayName: "Is Backed by a Node-Local hostPath Volume"
security.kubeapt.io/description: "A hostPath or local PersistentVolume hands pods a path on the node filesystem, so any workload that binds the claim can read or tamper with kubelet credentials and other tenants' data."
security.kubeapt.io/resource: "PersistentVolumes"
security.kubeapt.io/severity: "High"
security.kubeapt.io/remediation: "Back the volume with a CSI or network storage source and remove the node-local source. Fields: spec.hostPath, spec.local."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- persistentvolumes
validations:
- expression: |
!has(object.spec.hostPath) && !has(object.spec.local)
message: |
PersistentVolumes must not be backed by a node-local hostPath or local volume.Save it as persistentvolume-hostpath.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./persistentvolume-hostpath.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name persistentvolume-hostpath -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name persistentvolume-hostpath -A