Description
The PodSecurityPolicy allowed_capabilities list specifies Linux capabilities that containers may request in addition to their defaults. The allow-list does not itself grant these permissions to every container. Permit only what is needed after considering each capability’s function and the workload.
Some capabilities, such as NET_BIND_SERVICE, have legitimate uses; not every addition presents the same risk. PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25, so enforce restrictions with Pod Security Admission or a policy engine today.
Potential impact
- If unnecessary capabilities are actually added, a compromised container can use more system functions.
- Broad allow-lists shared by many workloads make least-privilege management harder.
Remediation
- Remove unnecessary
allowed_capabilitiesentries and list only required permissions. - Review actual Pod additions and default capabilities too. An empty allow-list does not remove every default capability.
- Limit access to exceptions to the workloads that need them, and verify enforcement after policy migration.
Examples
These partial legacy PSP examples omit some required fields and compare reducing additional capability permissions.
Before
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
allowed_capabilities = ["NET_BIND_SERVICE"]
}
}
The policy permits requests for NET_BIND_SERVICE. This may be needed to bind low-numbered ports, so check the actual requirement.
After
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
privileged = false
allow_privilege_escalation = false
}
}
The additional allowance is removed. Also review default-capability removal policies and actual Pod settings.