Review policy requirements to drop NET_RAW

Require removal of NET_RAW for workloads that do not need raw sockets.

Description

NET_RAW is a Linux capability allowing network functions such as raw and packet sockets. If restrictions are absent and a container actually holds it, a compromised process can misuse it. A policy that does not require dropping NET_RAW does not automatically add it to every container.

PodSecurityPolicy was removed in Kubernetes 1.25. Use Pod Security Admission or a policy engine for the required restrictions on current clusters.

Potential impact

  • Unnecessary packet generation or manipulation can be used in network attacks.
  • Dropping required capabilities can disrupt normal application functions.

Remediation

  • Where compatible, drop all capabilities and permit only those required; at minimum, drop unneeded NET_RAW. Check effective runtime permissions and application behavior.
  • Enforce the requirements with current admission policy. Do not directly use the legacy PSP required_drop_capabilities examples as policy for current clusters.

Examples

These legacy excerpts show only part of the removed PSP configuration. Other required fields and authorization to use the policy are omitted. The after value ALL requires dropping other capabilities as well as NET_RAW.

Before

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    required_drop_capabilities = [
      "KILL",
      "SYS_TIME",
    ]
  }
}

After

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    required_drop_capabilities = [
      "ALL",
    ]
  }
}

Explanation:

  • Before: KILL and SYS_TIME must be dropped, but NET_RAW is not explicitly included.
  • After: All capabilities must be dropped. Check that the application works under this restriction.

References