The repository is organized into the following directories:
Contains policies for validating Dockerfiles, such as:
- Preventing the
USERinstruction from being set toroot.
The Kubernetes/ directory contains policies for validating Kubernetes manifests, ensuring they adhere to security and configuration best practices. These policies enforce the following key requirements:
-
Prevent Pods from Running as Root:
- Ensures that all containers in a Deployment or Pod run as non-root users by checking the
runAsNonRootproperty in thesecurityContext.
- Ensures that all containers in a Deployment or Pod run as non-root users by checking the
-
Mandatory Security Context Configuration:
- Requires the use of
securityContextto explicitly define:runAsUser: Specifies a non-root user ID for the container.runAsGroup: Specifies a group ID for the container processes.fsGroup: Ensures proper permissions for shared storage volumes.
- Requires the use of
-
Disable Privilege Escalation:
- Ensures the
allowPrivilegeEscalationproperty is set tofalsefor all containers, reducing the risk of elevated privileges inside the container.
- Ensures the
-
Drop Unnecessary Capabilities:
- Ensures all Linux capabilities are dropped by default (
capabilities.drop: ["ALL"]), following the principle of least privilege.
- Ensures all Linux capabilities are dropped by default (
-
Read-Only Root Filesystem:
- Ensures that containers use a read-only root filesystem to prevent unnecessary write access, reducing the impact of potential attacks.
-
Disable Privileged Containers:
- Ensures the
privilegedproperty is set tofalseto restrict access to the host system.
- Ensures the
-
Enforce Seccomp Profiles:
- Requires containers to use the
RuntimeDefaultseccomp profile, which restricts unnecessary system calls and improves runtime security.
- Requires containers to use the
-
Restrict Host Network Usage:
- Ensures that
hostNetworkis explicitly set tofalse, preventing containers from accessing the host network.
- Ensures that
-
Disable Automatic Mounting of Service Account Tokens:
- Requires
automountServiceAccountTokento be set tofalse, reducing the risk of token misuse.
- Requires
These policies ensure that Kubernetes workloads are deployed securely, following industry best practices. They help to:
- Prevent privilege escalation.
- Reduce the attack surface of workloads.
- Enforce consistency in security settings across teams.