Review removal of NET_RAW capability

Drop unnecessary raw-network capability to reduce container privileges.

Description

If NET_RAW or ALL is absent from container securityContext.capabilities.drop, raw-network capability may remain available. Ordinary applications often do not need it.

Remove unnecessary capabilities in individual workloads as well as policy. Align workload settings with enforcement to provide actual protection.

Potential impact

  • The container may retain raw-network functionality.
  • Unnecessary network scanning or packet manipulation may be possible.
  • An attacker who compromises the application may gain stronger network privileges.

Remediation

  • Add ALL, or at least NET_RAW, to container capabilities.drop.
  • Use add only for required capabilities, and check that NET_RAW is not reintroduced.
  • Review privilege escalation alongside capability settings, and enforce standards with Pod Security Admission or a policy engine.

Examples

These are Linux Pod examples. Add NET_BIND_SERVICE only if the application actually requires it.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: example
spec:
  containers:
    - name: payment
      image: nginx
      securityContext:
        capabilities:
          drop:
            - SYS_ADMIN

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: example
spec:
  containers:
    - name: payment
      image: nginx
      securityContext:
        capabilities:
          drop:
            - ALL
          add:
            - NET_BIND_SERVICE

Explanation:

  • Before: Only SYS_ADMIN is dropped, so raw-network capability may remain.
  • After: ALL capabilities are dropped before adding only NET_BIND_SERVICE. Verify the required privileges and normal operation.

References