Container with added Linux capabilities

Limit added Linux capabilities to operations the application actually needs.

Description

Linux capabilities such as NET_ADMIN and SYS_TIME allow specific privileged operations, including network configuration or system-time changes. Adding unnecessary capabilities increases the actions available to an attacker who compromises the application.

The effect depends on the capability, namespaces and host access. Review the default capability set too; not every application needs all defaults.

Potential impact

A compromised process may perform unnecessary network or system operations or exploit other isolation weaknesses. Removing a required capability without testing can also disrupt application functions.

Remediation

  • Remove unnecessary capabilities from securityContext.capabilities.add.
  • Where possible, use drop: [ALL] and add back only required capabilities. Document each exception’s purpose and scope.
  • Combine this with non-root execution and protection against privilege escalation, and verify required functions.

Examples

These Pod examples compare added capabilities. Apply changes to the actual target Pod and check the image’s permission requirements.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: pod2
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4
      securityContext:
        allowPrivilegeEscalation: false
        capabilities:
          add: ["NET_ADMIN", "SYS_TIME"]

This adds NET_ADMIN and SYS_TIME. allowPrivilegeEscalation: false does not remove capabilities already granted.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: pod1
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4
      securityContext:
        allowPrivilegeEscalation: false

No additional capabilities are specified. This does not remove every runtime default capability; review drop settings separately.

References