Review Linux capability reduction for containers

Remove Linux capabilities the application does not need.

Description

Without container security_context.capabilities.drop, runtime defaults or added capabilities may remain. Unnecessary privileges increase the system functions a container can use and can expand its attack surface.

Linux containers should retain only required privileges. Start with drop = ["ALL"], add back only necessary capabilities, and test actual operation.

Potential impact

  • Unnecessary system privileges can increase the damage caused by an exploited vulnerability.
  • Removing required capabilities can prevent startup or normal application operations.

Remediation

  • Apply drop = ["ALL"] and allow only required capabilities through add. Review init containers as well.
  • Check the image’s runtime user and required system operations, then test before deployment. Capability reduction does not replace other security-context or host-isolation controls.

Examples

The existing nginx excerpts compare capability settings only. Use a maintained image and verify startup, file access and port binding after dropping privileges. Dropping every capability does not guarantee that this image will run correctly.

Before

hcl
resource "kubernetes_pod" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      security_context {
        capabilities {
          add = ["NET_BIND_SERVICE"]
        }
      }
    }
  }
}

After

hcl
resource "kubernetes_pod" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      security_context {
        capabilities {
          drop = ["ALL"]
        }
      }
    }
  }
}

Explanation:

  • Before: NET_BIND_SERVICE is added without explicitly dropping the default capabilities.
  • After: All capabilities are dropped. Separately assess any privileges essential to normal operation.

References