Description
Linux capabilities divide the permissions a container can use for network and system operations. Unnecessary additions through security_context.capabilities.add can increase what a compromised process can misuse. Effective permissions also depend on runtime defaults and drop settings.
NET_BIND_SERVICE can be needed for binding low-numbered ports and may already be in the default set. Removing an add entry does not by itself remove that capability from the effective set.
Potential impact
- Unnecessary capabilities can enable misuse of system or network permissions.
- Removing required permissions can prevent application startup or functionality.
Remediation
- Remove unnecessary
capabilities.addentries and inspect the running process’s actual permissions. Where compatible, consider starting withdrop = ["ALL"]and allowing only required capabilities. - Grant required exceptions only to the relevant workload and test startup, port binding and file access. Control allowed settings with Pod Security Admission or a policy engine.
Examples
These examples compare capability additions with a retained image. Use a maintained image for deployment. Runtime defaults can remain in the after example; it does not remove all capabilities.
Before
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
security_context {
capabilities {
add = ["NET_BIND_SERVICE"]
}
}
}
}
}
After
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
Explanation:
- Before: NET_BIND_SERVICE is explicitly added. Whether this increases permissions depends on the default set.
- After: The explicit addition is removed. Review required drop settings separately.