Kubernetes configuration permits unsafe sysctls

Unsafe sysctls can affect Pod isolation and node stability and should be permitted only where necessary.

Description

Using unsafe sysctls through workload securityContext.sysctls and node allow settings can affect isolation between Pods and node stability. Prefer safe sysctls supported by the Kubernetes and Linux kernel versions in use for ordinary applications.

Unsafe sysctls are disabled by default and must be explicitly enabled on the relevant nodes. The legacy PodSecurityPolicy field allowedUnsafeSysctls can also broaden permission. PSP was deprecated in Kubernetes 1.21 and removed in 1.25; use Pod Security Admission or another admission policy on current clusters.

Potential impact

  • Incorrect kernel settings can disrupt container behavior or node stability.
  • Other Pods on the node may suffer resource shortages or weaker isolation.
  • A Pod requesting a sysctl that is not permitted can fail to start, interrupting service startup.

Remediation

  • Remove unnecessary unsafe sysctl requests and allow settings. Check the supported versions and required values even for safe sysctls.
  • If an exception is essential, test its effects and restrict it to dedicated nodes with appropriate scheduling controls.
  • Verify Pod startup, resource use, and the operation of other workloads after the change.

Examples

These examples compare sysctl settings in a Deployment. Configure the image and command for the actual application.

Before

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: test-app
spec:
  selector:
    matchLabels:
      app: test-app
  template:
    metadata:
      labels:
        app: test-app
    spec:
      securityContext:
        sysctls:
          - name: kernel.sem
            value: "128 32768 128 4096"
      containers:
        - name: test-ubuntu
          image: ubuntu

kernel.sem is an unsafe sysctl. The Pod cannot start unless the node explicitly permits it; review its effects on resources and isolation before granting permission.

After

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: test-app-neg
spec:
  selector:
    matchLabels:
      app: test-app-neg
  template:
    metadata:
      labels:
        app: test-app-neg
    spec:
      securityContext:
        sysctls:
          - name: kernel.shm_rmid_forced
            value: "0"
          - name: net/ipv4/tcp_syncookies
            value: "1"
      containers:
        - name: test-ubuntu
          image: ubuntu

Both settings are in the Kubernetes safe sysctl list. The / separator in a sysctl name is supported from Kubernetes 1.25; check that the values suit the application.

References