Description
Without container security_context.capabilities.drop, runtime defaults or added capabilities may remain. Unnecessary privileges increase the system functions a container can use and can expand its attack surface.
Linux containers should retain only required privileges. Start with drop = ["ALL"], add back only necessary capabilities, and test actual operation.
Potential impact
- Unnecessary system privileges can increase the damage caused by an exploited vulnerability.
- Removing required capabilities can prevent startup or normal application operations.
Remediation
- Apply
drop = ["ALL"]and allow only required capabilities through add. Review init containers as well. - Check the image’s runtime user and required system operations, then test before deployment. Capability reduction does not replace other security-context or host-isolation controls.
Examples
The existing nginx excerpts compare capability settings only. Use a maintained image and verify startup, file access and port binding after dropping privileges. Dropping every capability does not guarantee that this image will run correctly.
Before
hcl
resource "kubernetes_pod" "example" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
security_context {
capabilities {
add = ["NET_BIND_SERVICE"]
}
}
}
}
}
After
hcl
resource "kubernetes_pod" "example" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
security_context {
capabilities {
drop = ["ALL"]
}
}
}
}
}
Explanation:
- Before: NET_BIND_SERVICE is added without explicitly dropping the default capabilities.
- After: All capabilities are dropped. Separately assess any privileges essential to normal operation.