Description
Access to pods/exec allows users to run commands available inside a container. The container’s runtime user and permissions also determine what those commands can access. This is sensitive because it provides direct entry into a running workload.
The impact can be greater when the container has a powerful service account or handles sensitive application data. Limit this access in production.
Potential impact
- Users can execute commands directly inside containers.
- Sensitive environment variables, files or tokens may become accessible.
- A compromised account may gain direct access to workload internals.
Remediation
- Remove unnecessary
pods/execpermissions from RBAC roles. - Allow production debugging only through approved accounts and procedures.
- Do not grant exec access by default in production namespaces.
Examples
RoleBindings are omitted. To reduce actual access, check grants from other roles as well as this one.
Before
yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: my-namespace
name: allow-exec
rules:
- apiGroups: [""]
resources: ["pods", "pods/exec"]
verbs: ["get", "list", "create"]
After
yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: my-namespace
name: allow-exec-neg
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "create"]
Explanation:
- Before: Access to
pods/execpermits command execution inside containers. - After: This role no longer grants exec access. Pod creation remains allowed and must be reviewed separately.