PodSecurityPolicy permits privileged containers

A PodSecurityPolicy that permits privileged execution allows container configurations with broad access to node resources.

Description

The legacy PodSecurityPolicy setting privileged: true permits privileged containers. On Linux, these containers receive all capabilities and can bypass several runtime isolation restrictions, giving them far more permissions than ordinary applications need. Allowing the mode in a policy does not automatically make every Pod privileged.

PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to restrict unnecessary privileged execution on current clusters.

Potential impact

  • Containers may gain broad access to host devices and system resources.
  • A container compromise can have a greater impact on the node or other workloads.

Remediation

  • Set privileged: false in legacy policies and remove privileged mode from actual workloads.
  • Grant only the capabilities required for specific tasks and restrict hostPath and host namespace sharing.
  • Limit essential system-tool exceptions by authorization and deployment scope, and verify enforcement and normal operation under the replacement policy.

Examples

These excerpts show privileged-mode controls in PSP for Kubernetes before 1.25. Other required policy fields are omitted.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: example
spec:
  privileged: true

Pods authorized to use this policy can request privileged execution.

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: example
spec:
  privileged: false

This policy does not allow privileged execution. Separately restrict excessive permissions granted through individual capabilities or other policies.

References