PSP does not require dropping NET_RAW

Without a required NET_RAW or ALL capability drop in PodSecurityPolicy, workloads may retain sensitive network privileges.

Description

If PodSecurityPolicy does not include NET_RAW or ALL in requiredDropCapabilities, Pods may retain raw networking capabilities. NET_RAW enables sensitive operations such as packet creation and warrants careful control.

Security policies should require removal of unnecessary capabilities rather than relying only on individual Pod settings. Apply this requirement directly to the policy where PSP is still in use.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. This article concerns legacy clusters or retained PSP resources. On current clusters, use Pod Security Admission or a policy engine such as Gatekeeper or Kyverno to enforce equivalent restrictions.

Potential impact

  • Pods may use raw networking capabilities for unintended network activity.
  • The network attack surface may increase.
  • Capability restrictions may become inconsistent across workloads.

Remediation

  • Include NET_RAW or ALL in the PSP's requiredDropCapabilities.
  • Review individual workloads and minimize added capabilities.
  • Include capability requirements in security policy change reviews.

Examples

These excerpts show only capability settings from legacy PSPs. Other required fields and authorization to use the policies are omitted.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted2
spec:
  requiredDropCapabilities:
    - KILL

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  requiredDropCapabilities:
    - ALL

Explanation:

  • Before: Does not require dropping NET_RAW or ALL, so sensitive capabilities may remain.
  • After: Requires dropping Linux capabilities, including NET_RAW, through ALL.

References