Description
The legacy PodSecurityPolicy setting privileged: true permits privileged containers. On Linux, these containers receive all capabilities and can bypass several runtime isolation restrictions, giving them far more permissions than ordinary applications need. Allowing the mode in a policy does not automatically make every Pod privileged.
PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to restrict unnecessary privileged execution on current clusters.
Potential impact
- Containers may gain broad access to host devices and system resources.
- A container compromise can have a greater impact on the node or other workloads.
Remediation
- Set
privileged: falsein legacy policies and remove privileged mode from actual workloads. - Grant only the capabilities required for specific tasks and restrict
hostPathand host namespace sharing. - Limit essential system-tool exceptions by authorization and deployment scope, and verify enforcement and normal operation under the replacement policy.
Examples
These excerpts show privileged-mode controls in PSP for Kubernetes before 1.25. Other required policy fields are omitted.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
privileged: true
Pods authorized to use this policy can request privileged execution.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
privileged: false
This policy does not allow privileged execution. Separately restrict excessive permissions granted through individual capabilities or other policies.