Review Kubernetes container Linux capability reduction

Drop default privileges and allow only the Linux capabilities the application needs.

Description

Containers can receive several Linux capabilities by default. Without securityContext.capabilities.drop, permissions the application does not need may remain. Adding a required capability through add does not remove existing defaults; check the runtime and applied policies for effective permissions.

Potential impact

  • The container may retain unnecessary system privileges.
  • Exploitation of an application vulnerability can have a greater impact.

Remediation

  • For Linux containers, use ALL in capabilities.drop where possible and allow only capabilities actually required through add. Test application startup and normal operation.
  • Remove privileged mode separately and combine capability reduction with non-root execution and prevention of privilege escalation. Verify that unnecessary capabilities are absent at runtime.

Examples

These Deployment excerpts compare container permissions only. Fields such as selector are omitted; separately check the actual image’s requirements and conditions for binding low ports.

Before

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: nginx-deployment
spec:
  template:
    spec:
      containers:
        - name: payment
          image: nginx
          securityContext:
            capabilities:
              add:
                - NET_BIND_SERVICE

NET_BIND_SERVICE is added without removing other default capabilities.

After

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: nginx-deployment
spec:
  template:
    spec:
      containers:
        - name: payment
          image: nginx
          securityContext:
            capabilities:
              drop:
                - ALL
              add:
                - NET_BIND_SERVICE

All default capabilities are dropped, then NET_BIND_SERVICE alone is requested again. Retain that capability only if it is actually needed.

References