Description
Policies that allow root execution or privileged containers can increase the permissions available after application compromise. An allowing policy does not make every container run as root; the root user, privileged mode and privilege escalation are distinct settings.
PodSecurityPolicy was removed in Kubernetes 1.25. Do not apply the legacy PSP examples to current clusters; use Pod Security Admission or a policy engine to enforce the required restrictions.
Potential impact
- A compromised process can misuse unnecessary file or system permissions.
- Privileged settings combined with host access can increase the impact of compromise.
Remediation
- Run actual containers as non-root and restrict privilege escalation and privileged mode. On current workloads, use supported security_context settings such as
run_as_non_root = true,allow_privilege_escalation = falseandprivileged = false, together with admission policy. - Configure a read-only root filesystem and required writable volumes, and minimize user and group permissions. Legacy PSPs can require
MustRunAsNonRootand suitable group ranges; also test actual image and file-permission compatibility.
Examples
These legacy excerpts show only part of the removed PSP configuration. Other required PSP settings and authorization to use it are omitted. fs_group concerns volume-access groups; that range alone does not constrain every process group.
Before
resource "kubernetes_pod_security_policy" "example" {
metadata {
name = "terraform-example"
}
spec {
privileged = true
allow_privilege_escalation = true
run_as_user {
rule = "RunAsAny"
}
fs_group {
rule = "MustRunAs"
range {
min = 0
max = 65535
}
}
}
}
After
resource "kubernetes_pod_security_policy" "example" {
metadata {
name = "terraform-example"
}
spec {
privileged = false
allow_privilege_escalation = false
read_only_root_filesystem = true
run_as_user {
rule = "MustRunAsNonRoot"
}
fs_group {
rule = "MustRunAs"
range {
min = 1
max = 65535
}
}
}
}
Explanation:
- Before: Root execution, privileged mode and privilege escalation are allowed. This does not force a pod’s actual user to be root.
- After: Non-root execution and a read-only root filesystem are required, while privileged mode and privilege escalation are restricted.