Root containers admitted

Allowing root execution and privilege escalation in PodSecurityPolicy can increase the impact of a compromised container.

Description

PodSecurityPolicy with runAsUser.rule: RunAsAny does not restrict execution as UID 0. The separate settings privileged: true and allowPrivilegeEscalation: true allow privileged containers and process privilege escalation, respectively. Unnecessary permissions can increase the impact of exploited vulnerabilities.

Use non-root execution, prevent privilege escalation and apply a read-only root filesystem together where appropriate.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. This article concerns legacy clusters or retained PSP resources. On current clusters, use Pod Security Admission or a policy engine such as Gatekeeper or Kyverno to enforce equivalent restrictions.

Potential impact

  • Compromised containers may be abused with greater privileges.
  • The impact on the host or sensitive files may increase.
  • Workload isolation may be weakened.

Remediation

  • Set privileged: false and allowPrivilegeEscalation: false in the PSP.
  • Restrict runAsUser.rule to MustRunAsNonRoot.
  • Apply readOnlyRootFilesystem: true and exclude root groups where suitable for the workload.

Examples

These excerpts show relevant legacy PSP fields; other required fields and authorization to use the policy are omitted. A read-only root filesystem is a separate control from non-root execution.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  privileged: true
  allowPrivilegeEscalation: true
  runAsUser:
    rule: "RunAsAny"
  supplementalGroups:
    rule: "RunAsAny"
  fsGroup:
    rule: "MustRunAs"
    ranges:
      - min: 0
        max: 65535

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  privileged: false
  allowPrivilegeEscalation: false
  requiredDropCapabilities:
    - ALL
  runAsUser:
    rule: "MustRunAsNonRoot"
  supplementalGroups:
    rule: "MustRunAs"
    ranges:
      - min: 1
        max: 65535
  fsGroup:
    rule: "MustRunAs"
    ranges:
      - min: 1
        max: 65535
  readOnlyRootFilesystem: true

Explanation:

  • Before: Allows root execution and privilege escalation, potentially increasing the impact of container compromise.
  • After: Requires non-root execution and prevents privilege escalation to improve isolation.

References