Description
AlwaysAllow does not restrict operations for requests that pass authentication. Authentication and authorization are separate: authenticated users, or anonymous requests that are permitted, can lose the intended permission boundaries. Review kube-apiserver and kubelet authorization separately.
Potential impact
- Unnecessary resource reads, changes or node operations may be permitted.
- A compromised account or workload can misuse control-plane or node permissions and affect other workloads.
Remediation
- For kube-apiserver, prepare required roles and bindings and replace
AlwaysAllowwith authorization that checks permissions, such as RBAC. - For kubelet, configure
Webhookauthorization and its required API-server connectivity and permissions. Do not set an RBAC mode directly on kubelet. - Review command arguments and configuration files together. Test that required requests succeed and unauthorized requests are denied.
Examples
These historical Kubernetes 1.6 API-server excerpts compare command arguments. Migrate to a supported version and configure the remaining control plane separately. Both examples disable anonymous authentication; the second requires appropriate RBAC roles and bindings.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
labels:
purpose: demonstrate-command
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args:
["--anonymous-auth=false", "--authorization-mode=AlwaysAllow"]
restartPolicy: OnFailure
AlwaysAllow authorizes authenticated requests without operation-specific permission restrictions.
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
labels:
purpose: demonstrate-command
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args:
["--anonymous-auth=false", "--authorization-mode=RBAC"]
restartPolicy: OnFailure
RBAC policies determine authorization. Prepare the permissions needed by administrators and system components first.