Pulumi Kubernetes PodSecurityPolicy permits privileged execution

Do not permit privileged execution for ordinary workloads through PodSecurityPolicy.

Description

Setting privileged: true in a PodSecurityPolicy lets Pods authorized to use it request privileged execution. Containers that actually run as privileged have weaker isolation, so a workload compromise may extend to the node. The policy permission does not automatically make every Pod privileged.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Apply equivalent restrictions with Pod Security Admission or a policy engine on current clusters.

Potential impact

  • Privileged workloads may gain excessive access to kernel functions and node resources.
  • A container compromise can affect the node and other workloads.

Remediation

  • Set privileged to false in legacy PodSecurityPolicies.
  • Check whether special tasks can use narrower capabilities, and isolate essential exceptions with separate policies and nodes.
  • During policy migration, verify actual workload permissions and enforced restrictions.

Examples

These partial Pulumi YAML examples use the historical policy/v1beta1 API. This resource is unavailable in Kubernetes v1.25 and later; other required policy fields are also omitted.

Before

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: kubernetes:policy/v1beta1:PodSecurityPolicy
    properties:
      metadata:
        name: example
      spec:
        privileged: true

The policy permits requests for privileged execution.

After

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: kubernetes:policy/v1beta1:PodSecurityPolicy
    properties:
      metadata:
        name: example
      spec:
        privileged: false

Privileged execution is no longer permitted by this policy. Other permissions, such as capabilities or host access, are not all removed by this change.

References