Review policies allowing containers to run as root

Apply non-root execution and privilege-escalation restrictions as separate controls.

Description

Policies that allow root execution or privileged containers can increase the permissions available after application compromise. An allowing policy does not make every container run as root; the root user, privileged mode and privilege escalation are distinct settings.

PodSecurityPolicy was removed in Kubernetes 1.25. Do not apply the legacy PSP examples to current clusters; use Pod Security Admission or a policy engine to enforce the required restrictions.

Potential impact

  • A compromised process can misuse unnecessary file or system permissions.
  • Privileged settings combined with host access can increase the impact of compromise.

Remediation

  • Run actual containers as non-root and restrict privilege escalation and privileged mode. On current workloads, use supported security_context settings such as run_as_non_root = true, allow_privilege_escalation = false and privileged = false, together with admission policy.
  • Configure a read-only root filesystem and required writable volumes, and minimize user and group permissions. Legacy PSPs can require MustRunAsNonRoot and suitable group ranges; also test actual image and file-permission compatibility.

Examples

These legacy excerpts show only part of the removed PSP configuration. Other required PSP settings and authorization to use it are omitted. fs_group concerns volume-access groups; that range alone does not constrain every process group.

Before

hcl
resource "kubernetes_pod_security_policy" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    privileged                 = true
    allow_privilege_escalation = true

    run_as_user {
      rule = "RunAsAny"
    }

    fs_group {
      rule = "MustRunAs"
      range {
        min = 0
        max = 65535
      }
    }
  }
}

After

hcl
resource "kubernetes_pod_security_policy" "example" {
  metadata {
    name = "terraform-example"
  }

  spec {
    privileged                 = false
    allow_privilege_escalation = false
    read_only_root_filesystem  = true

    run_as_user {
      rule = "MustRunAsNonRoot"
    }

    fs_group {
      rule = "MustRunAs"
      range {
        min = 1
        max = 65535
      }
    }
  }
}

Explanation:

  • Before: Root execution, privileged mode and privilege escalation are allowed. This does not force a pod’s actual user to be root.
  • After: Non-root execution and a read-only root filesystem are required, while privileged mode and privilege escalation are restricted.

References