Review Kubernetes image admission policy

Verify that required image policies are actually enforced at deployment.

Description

ImagePolicyWebhook is an admission plugin that lets an external backend decide whether images are allowed. Without a mechanism to enforce image policy, unapproved images may be deployed. Enabling this plugin alone does not verify signatures or vulnerabilities automatically; other admission controls can also enforce organizational policy.

Potential impact

  • Unapproved images or code from untrusted sources may run.
  • Inconsistent validation and exception handling can make supply-chain risks harder to control.

Remediation

  • Define the required registry, signature and image-approval policies, and configure admission controls that actually validate them.
  • For ImagePolicyWebhook, configure the plugin, required API enablement, AdmissionConfiguration and TLS backend connection together. Test whether requests are allowed when the backend fails, as well as normal approval and rejection outcomes.

Examples

These historical partial examples compare Kubernetes v1.30.0 arguments. Use a supported version and complete API server configuration. Configuration files, the TLS backend and required --runtime-config=imagepolicy.k8s.io/v1alpha1=true setting are omitted and must be supplied separately.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --enable-admission-plugins=AlwaysAdmit

AlwaysAdmit itself does not validate image policy. Also check other policy controls in the existing cluster.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --enable-admission-plugins=ImagePolicyWebhook
        - --admission-control-config-file=/etc/kubernetes/image-policy-webhook.yaml

The webhook plugin and configuration path are specified. Actual approval and rejection decisions require a policy backend and its connection configuration.

References