Description
PodSecurityPolicy with runAsUser.rule: RunAsAny does not restrict execution as UID 0. The separate settings privileged: true and allowPrivilegeEscalation: true allow privileged containers and process privilege escalation, respectively. Unnecessary permissions can increase the impact of exploited vulnerabilities.
Use non-root execution, prevent privilege escalation and apply a read-only root filesystem together where appropriate.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. This article concerns legacy clusters or retained PSP resources. On current clusters, use Pod Security Admission or a policy engine such as Gatekeeper or Kyverno to enforce equivalent restrictions.
Potential impact
- Compromised containers may be abused with greater privileges.
- The impact on the host or sensitive files may increase.
- Workload isolation may be weakened.
Remediation
- Set
privileged: falseandallowPrivilegeEscalation: falsein the PSP. - Restrict
runAsUser.ruletoMustRunAsNonRoot. - Apply
readOnlyRootFilesystem: trueand exclude root groups where suitable for the workload.
Examples
These excerpts show relevant legacy PSP fields; other required fields and authorization to use the policy are omitted. A read-only root filesystem is a separate control from non-root execution.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
spec:
privileged: true
allowPrivilegeEscalation: true
runAsUser:
rule: "RunAsAny"
supplementalGroups:
rule: "RunAsAny"
fsGroup:
rule: "MustRunAs"
ranges:
- min: 0
max: 65535
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
spec:
privileged: false
allowPrivilegeEscalation: false
requiredDropCapabilities:
- ALL
runAsUser:
rule: "MustRunAsNonRoot"
supplementalGroups:
rule: "MustRunAs"
ranges:
- min: 1
max: 65535
fsGroup:
rule: "MustRunAs"
ranges:
- min: 1
max: 65535
readOnlyRootFilesystem: true
Explanation:
- Before: Allows root execution and privilege escalation, potentially increasing the impact of container compromise.
- After: Requires non-root execution and prevents privilege escalation to improve isolation.