Review capability restrictions in legacy PodSecurityPolicy

Drop unnecessary Linux capabilities and minimize actual workload privileges.

Description

Linux capabilities control individual privileges available to containers. Unneeded capabilities can weaken isolation, so allow only the privileges the workload needs.

PodSecurityPolicy was deprecated in Kubernetes 1.21 and removed in 1.25. In legacy PSP environments, review requiredDropCapabilities together with allowed capabilities. On current clusters, enforce the necessary restrictions through Pod Security Admission or a policy engine.

Potential impact

  • Excessive container privileges can increase the impact of compromise.
  • Dropping capabilities without checking requirements can break application functions.

Remediation

  • Where possible, drop unnecessary capabilities and allow only those that are required. Review legacy PSP requiredDropCapabilities, its allowed list and actual container settings together.
  • On current clusters, apply equivalent restrictions through supported policies and test the workload. Retaining a PSP resource alone does not enforce policy in a current cluster.

Examples

These legacy policy/v1beta1 PSP excerpts show capability settings only. Other required strategies and permissions to use the policy are omitted. This resource is unavailable in Kubernetes 1.25 and later.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  privileged: false
  allowPrivilegeEscalation: false
  volumes:
    - configMap
    - secret

The excerpt does not require dropping default capabilities. Actual privileges also depend on runtime defaults and other policies.

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  privileged: false
  allowPrivilegeEscalation: false
  requiredDropCapabilities:
    - ALL
  volumes:
    - configMap
    - secret

The policy requires dropping ALL capabilities. Review necessary privileges and verify that the actual workload runs under this policy.

References