Review removal of NET_RAW from containers

Drop NET_RAW from containers that do not need raw sockets.

Description

NET_RAW is a Linux capability permitting network functions such as raw and packet sockets. Many ordinary applications do not need it, and a compromised process can misuse it if unnecessarily retained. Check runtime defaults together with added and dropped capabilities to determine effective permissions.

Potential impact

  • Unnecessary packet generation or manipulation functions can be misused.
  • Removing too many capabilities can affect required application behavior.

Remediation

  • Add unneeded NET_RAW to security_context.capabilities.drop. Where a stricter minimum-permission setup is compatible, consider dropping ALL and allowing only the capabilities that are needed.
  • Check capabilities added back and privileged mode, and test actual application behavior. Enforce the required criteria with Pod Security Admission or a policy engine.

Examples

These examples compare removing NET_RAW from the retained nginx configuration. Dropping every capability can affect user switching, ports or file operations, so ALL requires separate compatibility checks. Use a maintained image for deployment.

Before

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      security_context {
        capabilities {}
      }
    }
  }
}

After

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      security_context {
        capabilities {
          drop = ["NET_RAW"]
        }
      }
    }
  }
}

Explanation:

  • Before: No explicit capabilities are dropped. Check the effective runtime defaults.
  • After: NET_RAW is dropped. This does not remove every other default capability.

References