Description
Containers can receive several Linux capabilities by default. Without securityContext.capabilities.drop, permissions the application does not need may remain. Adding a required capability through add does not remove existing defaults; check the runtime and applied policies for effective permissions.
Potential impact
- The container may retain unnecessary system privileges.
- Exploitation of an application vulnerability can have a greater impact.
Remediation
- For Linux containers, use ALL in capabilities.drop where possible and allow only capabilities actually required through add. Test application startup and normal operation.
- Remove privileged mode separately and combine capability reduction with non-root execution and prevention of privilege escalation. Verify that unnecessary capabilities are absent at runtime.
Examples
These Deployment excerpts compare container permissions only. Fields such as selector are omitted; separately check the actual image’s requirements and conditions for binding low ports.
Before
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deployment
spec:
template:
spec:
containers:
- name: payment
image: nginx
securityContext:
capabilities:
add:
- NET_BIND_SERVICE
NET_BIND_SERVICE is added without removing other default capabilities.
After
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deployment
spec:
template:
spec:
containers:
- name: payment
image: nginx
securityContext:
capabilities:
drop:
- ALL
add:
- NET_BIND_SERVICE
All default capabilities are dropped, then NET_BIND_SERVICE alone is requested again. Retain that capability only if it is actually needed.