Kubernetes

Guidance on access control and workload operation for Kubernetes resources defined with Terraform.

Documentation

Article Path
Review effective AppArmor protection for containers terraform/kubernetes/missing_app_armor_config
Review container CPU limits terraform/kubernetes/cpu_limits_not_set
Review container CPU requests terraform/kubernetes/cpu_requests_not_set
Container shares the host PID namespace terraform/kubernetes/container_host_pid_is_true
Review container resource requests and limits terraform/kubernetes/container_resources_limits_undefined
Review added Linux capabilities in containers terraform/kubernetes/container_with_added_capabilities
Review CronJob start deadlines terraform/kubernetes/cronjob_deadline_not_configured
Review Deployment pod placement terraform/kubernetes/deployment_has_no_pod_anti_affinity
Review the Deployment PodDisruptionBudget terraform/kubernetes/deployment_without_pod_disruption_budget
Review container access to the Docker daemon socket terraform/kubernetes/docker_daemon_socket_is_exposed_to_containers
Review HPA Object metric references terraform/kubernetes/hpa_targets_invalid_object
Kubernetes PodSecurityPolicy permits host IPC sharing terraform/kubernetes/psp_allows_sharing_host_ipc
Pod shares the host IPC namespace terraform/kubernetes/shared_host_ipc_namespace
Kubernetes PodSecurityPolicy permits host network sharing terraform/kubernetes/psp_allows_containers_to_share_the_host_network_namespace
Pod shares the host network namespace terraform/kubernetes/shared_host_network_namespace
Review workload exposure through Kubernetes Ingress terraform/kubernetes/ingress_controller_exposes_workload
Review container memory limits terraform/kubernetes/memory_limits_not_defined
Review container memory requests terraform/kubernetes/memory_requests_not_defined
Review removal of NET_RAW from containers terraform/kubernetes/net_raw_capabilities_not_being_dropped
Review policy requirements to drop NET_RAW terraform/kubernetes/net_raw_capabilities_disabled_for_psp
Review Pod and container security contexts terraform/kubernetes/pod_or_container_without_security_context
Pod-creation permissions are too broad terraform/kubernetes/permissive_access_to_create_pods
Review NetworkPolicy pod selection terraform/kubernetes/network_policy_is_not_targeting_any_pod
Kubernetes PodSecurityPolicy permits privilege escalation terraform/kubernetes/psp_allows_privilege_escalation
Privilege escalation allowed in a Kubernetes container terraform/kubernetes/privilege_escalation_allowed
Kubernetes container runs in privileged mode terraform/kubernetes/container_is_privileged
Kubernetes PodSecurityPolicy permits privileged execution terraform/kubernetes/psp_set_to_privileged
Review container readiness probes terraform/kubernetes/readiness_probe_is_not_configured
Review policies allowing containers to run as root terraform/kubernetes/root_containers_admitted
SYS_ADMIN capability added to a Kubernetes container terraform/kubernetes/containers_with_sys_admin_capabilities
Review container seccomp profiles terraform/kubernetes/secoomp_profile_is_not_configured
Review exposure of Secrets in environment variables terraform/kubernetes/secrets_as_environment_variables
RBAC Role has Secret-read permissions terraform/kubernetes/rbac_roles_with_read_secrets_permissions
Review ServiceAccount sharing terraform/kubernetes/shared_service_account
ServiceAccount name is not specified terraform/kubernetes/service_account_name_undefined_or_empty
Review ServiceAccount token automounting terraform/kubernetes/service_account_token_automount_not_disabled
Review ServiceAccount access to Secrets terraform/kubernetes/service_account_allows_access_secrets
Review Kubernetes NodePort access scope terraform/kubernetes/service_type_is_nodeport
Review the StatefulSet headless Service association terraform/kubernetes/statefulset_without_service_name
Review the StatefulSet PodDisruptionBudget terraform/kubernetes/statefulset_without_pod_disruption_budget
Review StatefulSet persistent-storage requirements terraform/kubernetes/statefulset_requests_storage
Tiller (Helm v2) deployed in a Kubernetes environment terraform/kubernetes/tiller_is_deployed
Kubernetes security policy permits Unmasked proc mounts terraform/kubernetes/container_runs_unmasked
Kubernetes configuration permits unsafe sysctls terraform/kubernetes/cluster_allows_unsafe_sysctls
Review whether workload host_port is needed terraform/kubernetes/workload_host_port_not_specified
Review cluster-admin ClusterRoleBinding permissions terraform/kubernetes/cluster_admin_role_binding_with_super_user_permissions
Review the need for container liveness probes terraform/kubernetes/liveness_probe_is_not_defined
Review use of the Kubernetes default namespace terraform/kubernetes/using_default_namespace
Review default ServiceAccount permissions and token automounting terraform/kubernetes/default_service_account_in_use
RoleBinding targets the default ServiceAccount terraform/kubernetes/role_binding_to_default_service_account
Kubernetes workload uses sensitive host directories terraform/kubernetes/workload_mounting_with_sensitive_os_directory
Review protection of Kubernetes OS directory mounts terraform/kubernetes/volume_mount_with_os_directory_write_permissions
Review exposure of Kubernetes LoadBalancer Services terraform/kubernetes/service_with_external_load_balancer
Review container image digest pinning terraform/kubernetes/image_without_digest
Review hostPath use in ordinary Kubernetes workloads terraform/kubernetes/non_kube_system_pod_with_host_mount
Review volume claim access modes terraform/kubernetes/incorrect_volume_claim_access_mode_read_write_once
Review Kubernetes metadata label syntax terraform/kubernetes/metadata_label_is_invalid
Review container image references terraform/kubernetes/invalid_image
Kubernetes PodSecurityPolicy permits additional capabilities terraform/kubernetes/psp_with_added_capabilities
Review Linux capability reduction for containers terraform/kubernetes/no_drop_capabilities_for_containers
Review container image pull policies terraform/kubernetes/image_pull_policy_of_container_is_not_always
Review container root filesystem write protection terraform/kubernetes/root_container_not_mounted_as_read_only

Related pages62

Review effective AppArmor protection for containers

Check node support and the effective profile, then apply the required AppArmor restrictions.

Review container CPU limits

Assess CPU caps and throttling against workload requirements.

Review container CPU requests

Set scheduling requirements according to the workload’s actual CPU needs.

Container shares the host PID namespace

Disable host_pid for pods that do not need access to host processes.

Review container resource requests and limits

Configure CPU and memory requests and usage limits for the actual workload.

Review added Linux capabilities in containers

Verify the need for added permissions and minimize the effective capability set.

Review CronJob start deadlines

Choose an allowed start delay that matches the job’s timing requirements.

Review Deployment pod placement

Distribute replicas across the required failure domains and inspect actual placement.

Review the Deployment PodDisruptionBudget

Set an acceptable voluntary disruption budget for maintenance.

Review container access to the Docker daemon socket

Do not expose the host Docker daemon socket to ordinary applications.

Review HPA Object metric references

Configure the measured object separately from the workload that will be scaled.

Kubernetes PodSecurityPolicy permits host IPC sharing

Block unnecessary sharing of the host IPC namespace through admission policy.

Pod shares the host IPC namespace

Disable host_ipc for pods that do not need host IPC resources.

Kubernetes PodSecurityPolicy permits host network sharing

Restrict unnecessary host network sharing in admission policy.

Pod shares the host network namespace

Use a separate network namespace for pods that do not need host networking.

Review workload exposure through Kubernetes Ingress

Verify that the actual Ingress path, authentication and TLS configuration match service requirements.

Review container memory limits

Check memory limits and their effective values against actual usage.

Review container memory requests

Check memory requests and effective defaults against the workload’s actual needs.

Review removal of NET_RAW from containers

Drop NET_RAW from containers that do not need raw sockets.

Review policy requirements to drop NET_RAW

Require removal of NET_RAW for workloads that do not need raw sockets.

Review Pod and container security contexts

Check effective runtime privileges and apply the required security context.

Pod-creation permissions are too broad

Limit Pod creation to required identities and control the workload configurations they may deploy.

Review NetworkPolicy pod selection

Verify that the policy selects the intended namespace and pods.

Kubernetes PodSecurityPolicy permits privilege escalation

Enforce privilege-escalation restrictions through admission policy to maintain least privilege across workloads.

Privilege escalation allowed in a Kubernetes container

Configure container privilege escalation settings to restrict gaining additional permissions through executable files.

Kubernetes container runs in privileged mode

Disable unnecessary privileged mode in Kubernetes containers.

Kubernetes PodSecurityPolicy permits privileged execution

Prohibit privileged execution for ordinary workloads through admission policy.

Review container readiness probes

Check readiness using the application’s actual ability to serve requests.

Review policies allowing containers to run as root

Apply non-root execution and privilege-escalation restrictions as separate controls.

SYS_ADMIN capability added to a Kubernetes container

Do not grant containers the SYS_ADMIN capability without a justified need.

Review container seccomp profiles

Apply an appropriate seccomp profile to Linux containers and verify actual behavior.

Review exposure of Secrets in environment variables

Control how Secrets are delivered and how logs and diagnostic tools handle them.

RBAC Role has Secret-read permissions

Restrict Secret-reading permissions to required identities and namespaces.

Review ServiceAccount sharing

Separate ServiceAccounts for workloads with different purposes and permission needs.

ServiceAccount name is not specified

Specify the account a pod should use and verify its actual permissions.

Review ServiceAccount token automounting

Disable automatic token mounts for pods that do not need Kubernetes API tokens.

Review ServiceAccount access to Secrets

Limit Secret-reading permissions bound to a ServiceAccount to what the workload needs.

Review Kubernetes NodePort access scope

Verify whether NodePort is needed and restrict actual access to the nodes.

Review the StatefulSet headless Service association

Configure a headless Service for the StatefulSet’s stable network identities.

Review the StatefulSet PodDisruptionBudget

Define how many voluntary disruptions the stateful application can tolerate.

Review StatefulSet persistent-storage requirements

Review persistence needs together with capacity and retention policies.

Tiller (Helm v2) deployed in a Kubernetes environment

Remove unsupported Helm v2 Tiller components and migrate to a supported deployment workflow.

Kubernetes security policy permits Unmasked proc mounts

Remove permission for Unmasked proc mounts to retain default /proc protections.

Kubernetes configuration permits unsafe sysctls

Restrict unsafe sysctl permissions to protect Pod isolation and node stability.

Review whether workload host_port is needed

Configure node port mappings and access scope only when host_port is required.

Review cluster-admin ClusterRoleBinding permissions

Grant cluster-admin only to identities that require full cluster administration.

Review the need for container liveness probes

Use liveness probes for unhealthy states that a restart can resolve.

Review use of the Kubernetes default namespace

Specify namespaces and configure RBAC, network and resource policies together.

Review default ServiceAccount permissions and token automounting

Separate workload permissions and avoid automounting API tokens where they are not needed.

RoleBinding targets the default ServiceAccount

Avoid unnecessary grants to the default account and use accounts with distinct purposes.