Review added Linux capabilities in containers

Verify the need for added permissions and minimize the effective capability set.

Description

Linux capabilities divide the permissions a container can use for network and system operations. Unnecessary additions through security_context.capabilities.add can increase what a compromised process can misuse. Effective permissions also depend on runtime defaults and drop settings.

NET_BIND_SERVICE can be needed for binding low-numbered ports and may already be in the default set. Removing an add entry does not by itself remove that capability from the effective set.

Potential impact

  • Unnecessary capabilities can enable misuse of system or network permissions.
  • Removing required permissions can prevent application startup or functionality.

Remediation

  • Remove unnecessary capabilities.add entries and inspect the running process’s actual permissions. Where compatible, consider starting with drop = ["ALL"] and allowing only required capabilities.
  • Grant required exceptions only to the relevant workload and test startup, port binding and file access. Control allowed settings with Pod Security Admission or a policy engine.

Examples

These examples compare capability additions with a retained image. Use a maintained image for deployment. Runtime defaults can remain in the after example; it does not remove all capabilities.

Before

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      security_context {
        capabilities {
          add = ["NET_BIND_SERVICE"]
        }
      }
    }
  }
}

After

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

Explanation:

  • Before: NET_BIND_SERVICE is explicitly added. Whether this increases permissions depends on the default set.
  • After: The explicit addition is removed. Review required drop settings separately.

References