Kubernetes PodSecurityPolicy permits privileged execution

Prohibit privileged execution for ordinary workloads through admission policy.

Description

A PodSecurityPolicy that permits privileged execution allows workloads using it to request broad privileges. Containers actually running as privileged have substantially weaker isolation, so a compromise may affect the node. Policy permission alone does not make every Pod privileged.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Use Pod Security Admission or a policy engine to enforce restrictions on current clusters.

Potential impact

  • Workloads may be deployed with more permissions than they need.
  • A privileged container compromise can affect the node and other workloads.

Remediation

  • Explicitly set spec.privileged = false in legacy PSPs.
  • Check whether special operational tasks can use narrower permissions, and isolate necessary exceptions with separate policies and nodes.
  • Also restrict privilege escalation, capabilities and host namespace sharing.

Examples

These partial examples compare privileged permissions in a historical PSP environment. Other required policy settings are omitted.

Before

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    privileged = true
  }
}

Pods authorized to use this policy can request privileged execution.

After

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    privileged = false
  }
}

This policy does not permit privileged execution. Review permissions from other policies and the actual Pod permissions too.

References