Description
A PodSecurityPolicy that permits privileged execution allows workloads using it to request broad privileges. Containers actually running as privileged have substantially weaker isolation, so a compromise may affect the node. Policy permission alone does not make every Pod privileged.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Use Pod Security Admission or a policy engine to enforce restrictions on current clusters.
Potential impact
- Workloads may be deployed with more permissions than they need.
- A privileged container compromise can affect the node and other workloads.
Remediation
- Explicitly set
spec.privileged = falsein legacy PSPs. - Check whether special operational tasks can use narrower permissions, and isolate necessary exceptions with separate policies and nodes.
- Also restrict privilege escalation, capabilities and host namespace sharing.
Examples
These partial examples compare privileged permissions in a historical PSP environment. Other required policy settings are omitted.
Before
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
privileged = true
}
}
Pods authorized to use this policy can request privileged execution.
After
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
privileged = false
}
}
This policy does not permit privileged execution. Review permissions from other policies and the actual Pod permissions too.