Kubernetes PodSecurityPolicy permits additional capabilities

Limit the Linux capabilities permitted by policy to those workloads actually need.

Description

The PodSecurityPolicy allowed_capabilities list specifies Linux capabilities that containers may request in addition to their defaults. The allow-list does not itself grant these permissions to every container. Permit only what is needed after considering each capability’s function and the workload.

Some capabilities, such as NET_BIND_SERVICE, have legitimate uses; not every addition presents the same risk. PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25, so enforce restrictions with Pod Security Admission or a policy engine today.

Potential impact

  • If unnecessary capabilities are actually added, a compromised container can use more system functions.
  • Broad allow-lists shared by many workloads make least-privilege management harder.

Remediation

  • Remove unnecessary allowed_capabilities entries and list only required permissions.
  • Review actual Pod additions and default capabilities too. An empty allow-list does not remove every default capability.
  • Limit access to exceptions to the workloads that need them, and verify enforcement after policy migration.

Examples

These partial legacy PSP examples omit some required fields and compare reducing additional capability permissions.

Before

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    allowed_capabilities = ["NET_BIND_SERVICE"]
  }
}

The policy permits requests for NET_BIND_SERVICE. This may be needed to bind low-numbered ports, so check the actual requirement.

After

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    privileged                 = false
    allow_privilege_escalation = false
  }
}

The additional allowance is removed. Also review default-capability removal policies and actual Pod settings.

References