Description
If NET_RAW or ALL is absent from container securityContext.capabilities.drop, raw-network capability may remain available. Ordinary applications often do not need it.
Remove unnecessary capabilities in individual workloads as well as policy. Align workload settings with enforcement to provide actual protection.
Potential impact
- The container may retain raw-network functionality.
- Unnecessary network scanning or packet manipulation may be possible.
- An attacker who compromises the application may gain stronger network privileges.
Remediation
- Add
ALL, or at leastNET_RAW, to containercapabilities.drop. - Use
addonly for required capabilities, and check thatNET_RAWis not reintroduced. - Review privilege escalation alongside capability settings, and enforce standards with Pod Security Admission or a policy engine.
Examples
These are Linux Pod examples. Add NET_BIND_SERVICE only if the application actually requires it.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: example
spec:
containers:
- name: payment
image: nginx
securityContext:
capabilities:
drop:
- SYS_ADMIN
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: example
spec:
containers:
- name: payment
image: nginx
securityContext:
capabilities:
drop:
- ALL
add:
- NET_BIND_SERVICE
Explanation:
- Before: Only SYS_ADMIN is dropped, so raw-network capability may remain.
- After: ALL capabilities are dropped before adding only NET_BIND_SERVICE. Verify the required privileges and normal operation.