Description
A policy permitting container privilege escalation can leave paths for gaining additional permissions through setuid executables or file capabilities. Actual privilege gain also depends on Pod settings and executable files. Setting allow_privilege_escalation = false does not remove permissions already held.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Apply equivalent restrictions through Pod Security Admission or a policy engine today.
Potential impact
- The policy may fail to prevent an unsafe setting in an individual Pod.
- A compromised process may abuse available executables to gain additional permissions.
Remediation
- Explicitly set
spec.allow_privilege_escalationtofalsein legacy PSPs. - Prohibit privileged mode and
SYS_ADMIN, which are incompatible with this restriction, and limit other unnecessary capabilities. - Check actual workloads and other applicable policies, and verify that restrictions remain enforced after migration.
Examples
These partial examples target historical clusters supporting PSP. Other required policy fields are omitted to compare privilege-escalation permission.
Before
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
allow_privilege_escalation = true
}
}
The policy does not prohibit Pods from allowing privilege escalation. This does not mean every container actually gains additional permissions.
After
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
allow_privilege_escalation = false
}
}
This policy prevents running containers that allow privilege escalation. Existing permissions must still be minimized separately.