Description
A legacy PodSecurityPolicy that permits allowPrivilegeEscalation allows container configurations that can gain additional privileges through setuid, setgid, or file capabilities when executing programs. Restrict this to false for ordinary workloads. It does not remove existing permissions or prevent every kernel exploit.
PSP was deprecated in Kubernetes 1.21 and removed in 1.25. On current clusters, use the Restricted policy in Pod Security Admission or another admission policy together with workload security contexts.
Potential impact
- A compromised process may have more opportunities to use executables that grant additional privileges.
- Excessive permissions or host access can increase the impact of a container compromise.
Remediation
- Set
allowPrivilegeEscalation: falsein legacy policies and restrictprivilegedand unnecessary capabilities. - Remove privileged mode or
SYS_ADMINfrom actual containers before enforcing this restriction; those settings are incompatible with preventing privilege escalation. - Verify that the replacement policy is enforced and that applications previously relying on setuid or similar behavior still work.
Examples
These excerpts show only the relevant PSP fields for Kubernetes before 1.25. Other required policy fields are omitted.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: privileged
spec:
privileged: true
allowPrivilegeEscalation: true
The policy permits both privileged execution and privilege escalation. Actual use depends on policy enforcement and authorization to use it.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: privileged
spec:
privileged: false
allowPrivilegeEscalation: false
Privileged execution is also prohibited so that it aligns with the intent of allowPrivilegeEscalation: false. Check that another policy cannot grant broader permissions.