RBAC permits command execution in containers

Access to pods/exec allows command execution inside running containers and requires strict control.

Description

Access to pods/exec allows users to run commands available inside a container. The container’s runtime user and permissions also determine what those commands can access. This is sensitive because it provides direct entry into a running workload.

The impact can be greater when the container has a powerful service account or handles sensitive application data. Limit this access in production.

Potential impact

  • Users can execute commands directly inside containers.
  • Sensitive environment variables, files or tokens may become accessible.
  • A compromised account may gain direct access to workload internals.

Remediation

  • Remove unnecessary pods/exec permissions from RBAC roles.
  • Allow production debugging only through approved accounts and procedures.
  • Do not grant exec access by default in production namespaces.

Examples

RoleBindings are omitted. To reduce actual access, check grants from other roles as well as this one.

Before

yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  namespace: my-namespace
  name: allow-exec
rules:
  - apiGroups: [""]
    resources: ["pods", "pods/exec"]
    verbs: ["get", "list", "create"]

After

yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  namespace: my-namespace
  name: allow-exec-neg
rules:
  - apiGroups: [""]
    resources: ["pods"]
    verbs: ["get", "list", "create"]

Explanation:

  • Before: Access to pods/exec permits command execution inside containers.
  • After: This role no longer grants exec access. Pod creation remains allowed and must be reviewed separately.

References