Description
Linux capabilities control individual privileges available to containers. Unneeded capabilities can weaken isolation, so allow only the privileges the workload needs.
PodSecurityPolicy was deprecated in Kubernetes 1.21 and removed in 1.25. In legacy PSP environments, review requiredDropCapabilities together with allowed capabilities. On current clusters, enforce the necessary restrictions through Pod Security Admission or a policy engine.
Potential impact
- Excessive container privileges can increase the impact of compromise.
- Dropping capabilities without checking requirements can break application functions.
Remediation
- Where possible, drop unnecessary capabilities and allow only those that are required. Review legacy PSP requiredDropCapabilities, its allowed list and actual container settings together.
- On current clusters, apply equivalent restrictions through supported policies and test the workload. Retaining a PSP resource alone does not enforce policy in a current cluster.
Examples
These legacy policy/v1beta1 PSP excerpts show capability settings only. Other required strategies and permissions to use the policy are omitted. This resource is unavailable in Kubernetes 1.25 and later.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
spec:
privileged: false
allowPrivilegeEscalation: false
volumes:
- configMap
- secret
The excerpt does not require dropping default capabilities. Actual privileges also depend on runtime defaults and other policies.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
spec:
privileged: false
allowPrivilegeEscalation: false
requiredDropCapabilities:
- ALL
volumes:
- configMap
- secret
The policy requires dropping ALL capabilities. Review necessary privileges and verify that the actual workload runs under this policy.