Description
Without admission policies restricting privileged execution, privilege escalation and host access, Pods may receive unnecessary privileges. Apply security-context restrictions appropriate to workload requirements.
The legacy SecurityContextDeny plugin was deprecated in Kubernetes 1.27 and removed in 1.30. Use Pod Security Admission or a supported policy engine on current clusters instead of attempting to enable the removed plugin.
Potential impact
- Unrestricted security contexts can permit privileged containers or unnecessary permissions.
- Compromised workloads may have a greater impact on the host or other resources.
Remediation
- Restrict security contexts with an appropriate Pod Security Admission policy level or a supported policy engine.
- Review actual workloads and warning or audit results before enforcing restrictions.
- Approve only necessary exceptions and test that new Pod requests receive the intended restrictions.
Examples
These excerpts compare arguments on Kubernetes 1.24, where SecurityContextDeny still existed. They do not recommend deploying an unsupported version; the plugin setting in the second example is unavailable in Kubernetes 1.30 and later. Remaining control-plane settings are omitted.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.24.17
command: ["kube-apiserver"]
args: ["--disable-admission-plugins=SecurityContextDeny"]
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.24.17
command: ["kube-apiserver"]
args:
["--enable-admission-plugins=SecurityContextDeny"]
Explanation:
- Before: Explicitly disables the legacy plugin. Check other applicable admission policies separately.
- After: Historically enabled the plugin. Replace it with supported Pod security policies in current environments.