Authorization mode is set to AlwaysAllow

Use component-appropriate authorization policies instead of AlwaysAllow.

Description

AlwaysAllow does not restrict operations for requests that pass authentication. Authentication and authorization are separate: authenticated users, or anonymous requests that are permitted, can lose the intended permission boundaries. Review kube-apiserver and kubelet authorization separately.

Potential impact

  • Unnecessary resource reads, changes or node operations may be permitted.
  • A compromised account or workload can misuse control-plane or node permissions and affect other workloads.

Remediation

  • For kube-apiserver, prepare required roles and bindings and replace AlwaysAllow with authorization that checks permissions, such as RBAC.
  • For kubelet, configure Webhook authorization and its required API-server connectivity and permissions. Do not set an RBAC mode directly on kubelet.
  • Review command arguments and configuration files together. Test that required requests succeed and unauthorized requests are denied.

Examples

These historical Kubernetes 1.6 API-server excerpts compare command arguments. Migrate to a supported version and configure the remaining control plane separately. Both examples disable anonymous authentication; the second requires appropriate RBAC roles and bindings.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
  labels:
    purpose: demonstrate-command
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args:
        ["--anonymous-auth=false", "--authorization-mode=AlwaysAllow"]
  restartPolicy: OnFailure

AlwaysAllow authorizes authenticated requests without operation-specific permission restrictions.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
  labels:
    purpose: demonstrate-command
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args:
        ["--anonymous-auth=false", "--authorization-mode=RBAC"]
  restartPolicy: OnFailure

RBAC policies determine authorization. Prepare the permissions needed by administrators and system components first.

References