Review policies replacing SecurityContextDeny

Restrict Pod security contexts with policies supported by the actual Kubernetes version.

Description

Without admission policies restricting privileged execution, privilege escalation and host access, Pods may receive unnecessary privileges. Apply security-context restrictions appropriate to workload requirements.

The legacy SecurityContextDeny plugin was deprecated in Kubernetes 1.27 and removed in 1.30. Use Pod Security Admission or a supported policy engine on current clusters instead of attempting to enable the removed plugin.

Potential impact

  • Unrestricted security contexts can permit privileged containers or unnecessary permissions.
  • Compromised workloads may have a greater impact on the host or other resources.

Remediation

  • Restrict security contexts with an appropriate Pod Security Admission policy level or a supported policy engine.
  • Review actual workloads and warning or audit results before enforcing restrictions.
  • Approve only necessary exceptions and test that new Pod requests receive the intended restrictions.

Examples

These excerpts compare arguments on Kubernetes 1.24, where SecurityContextDeny still existed. They do not recommend deploying an unsupported version; the plugin setting in the second example is unavailable in Kubernetes 1.30 and later. Remaining control-plane settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.24.17
      command: ["kube-apiserver"]
      args: ["--disable-admission-plugins=SecurityContextDeny"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.24.17
      command: ["kube-apiserver"]
      args:
        ["--enable-admission-plugins=SecurityContextDeny"]

Explanation:

  • Before: Explicitly disables the legacy plugin. Check other applicable admission policies separately.
  • After: Historically enabled the plugin. Replace it with supported Pod security policies in current environments.

References