initcontainer-poststart-httpget-host
A postStart HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node each time an init container starts, reaching internal endpoints closed to pods and triggering side effects there.
!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
!has(ic.lifecycle) ||
!has(ic.lifecycle.postStart) ||
!has(ic.lifecycle.postStart.httpGet) ||
!has(ic.lifecycle.postStart.httpGet.host) ||
ic.lifecycle.postStart.httpGet.host == ""
)
spec.initContainers[*].lifecycle.postStart.httpGet.host must be undefined or empty ("").
Remove the host field so the hook targets the pod IP, or set it to an empty string. Field: spec.initContainers[*].lifecycle.postStart.httpGet.host.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: initcontainer-poststart-httpget-host
annotations:
kubeapt.io/uuid: "fbef4cf3-cf91-4c11-af0b-ab80b64edff8"
security.kubeapt.io/displayName: "postStart Hook Targets an Arbitrary Host"
security.kubeapt.io/description: "A postStart HTTP hook aimed at another host makes the kubelet call an arbitrary URL from the node each time an init container starts, reaching internal endpoints closed to pods and triggering side effects there."
security.kubeapt.io/resource: "InitContainers"
security.kubeapt.io/severity: "Low"
security.kubeapt.io/remediation: "Remove the host field so the hook targets the pod IP, or set it to an empty string. Field: spec.initContainers[*].lifecycle.postStart.httpGet.host."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- pods
validations:
- expression: |
!has(object.spec.initContainers) || object.spec.initContainers.all(ic,
!has(ic.lifecycle) ||
!has(ic.lifecycle.postStart) ||
!has(ic.lifecycle.postStart.httpGet) ||
!has(ic.lifecycle.postStart.httpGet.host) ||
ic.lifecycle.postStart.httpGet.host == ""
)
message: |
spec.initContainers[*].lifecycle.postStart.httpGet.host must be undefined or empty ("").Save it as initcontainer-poststart-httpget-host.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./initcontainer-poststart-httpget-host.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name initcontainer-poststart-httpget-host -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name initcontainer-poststart-httpget-host -A