Description
Using unsafe sysctls through workload securityContext.sysctls and node allow settings can affect isolation between Pods and node stability. Prefer safe sysctls supported by the Kubernetes and Linux kernel versions in use for ordinary applications.
Unsafe sysctls are disabled by default and must be explicitly enabled on the relevant nodes. The legacy PodSecurityPolicy field allowedUnsafeSysctls can also broaden permission. PSP was deprecated in Kubernetes 1.21 and removed in 1.25; use Pod Security Admission or another admission policy on current clusters.
Potential impact
- Incorrect kernel settings can disrupt container behavior or node stability.
- Other Pods on the node may suffer resource shortages or weaker isolation.
- A Pod requesting a sysctl that is not permitted can fail to start, interrupting service startup.
Remediation
- Remove unnecessary unsafe sysctl requests and allow settings. Check the supported versions and required values even for safe sysctls.
- If an exception is essential, test its effects and restrict it to dedicated nodes with appropriate scheduling controls.
- Verify Pod startup, resource use, and the operation of other workloads after the change.
Examples
These examples compare sysctl settings in a Deployment. Configure the image and command for the actual application.
Before
apiVersion: apps/v1
kind: Deployment
metadata:
name: test-app
spec:
selector:
matchLabels:
app: test-app
template:
metadata:
labels:
app: test-app
spec:
securityContext:
sysctls:
- name: kernel.sem
value: "128 32768 128 4096"
containers:
- name: test-ubuntu
image: ubuntu
kernel.sem is an unsafe sysctl. The Pod cannot start unless the node explicitly permits it; review its effects on resources and isolation before granting permission.
After
apiVersion: apps/v1
kind: Deployment
metadata:
name: test-app-neg
spec:
selector:
matchLabels:
app: test-app-neg
template:
metadata:
labels:
app: test-app-neg
spec:
securityContext:
sysctls:
- name: kernel.shm_rmid_forced
value: "0"
- name: net/ipv4/tcp_syncookies
value: "1"
containers:
- name: test-ubuntu
image: ubuntu
Both settings are in the Kubernetes safe sysctl list. The / separator in a sysctl name is supported from Kubernetes 1.25; check that the values suit the application.