Description
Setting privileged: true in a PodSecurityPolicy lets Pods authorized to use it request privileged execution. Containers that actually run as privileged have weaker isolation, so a workload compromise may extend to the node. The policy permission does not automatically make every Pod privileged.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Apply equivalent restrictions with Pod Security Admission or a policy engine on current clusters.
Potential impact
- Privileged workloads may gain excessive access to kernel functions and node resources.
- A container compromise can affect the node and other workloads.
Remediation
- Set
privilegedtofalsein legacy PodSecurityPolicies. - Check whether special tasks can use narrower capabilities, and isolate essential exceptions with separate policies and nodes.
- During policy migration, verify actual workload permissions and enforced restrictions.
Examples
These partial Pulumi YAML examples use the historical policy/v1beta1 API. This resource is unavailable in Kubernetes v1.25 and later; other required policy fields are also omitted.
Before
name: aws-eks
runtime: yaml
resources:
example:
type: kubernetes:policy/v1beta1:PodSecurityPolicy
properties:
metadata:
name: example
spec:
privileged: true
The policy permits requests for privileged execution.
After
name: aws-eks
runtime: yaml
resources:
example:
type: kubernetes:policy/v1beta1:PodSecurityPolicy
properties:
metadata:
name: example
spec:
privileged: false
Privileged execution is no longer permitted by this policy. Other permissions, such as capabilities or host access, are not all removed by this change.