8 ms·
Kubernetes Hardening Guidance [pdf]
- SoftTalker 4y agoI didn't read this, but it's really tiresome to hear about having to "harden" systems in 2022. They should be "hard" by default. If you need to soften them to make them easier to work with internally, that should be what needs a checklist and instructions.
- Kalium 4y agoLooking at the guide, much of the hardening is above and beyond anything any Kubernetes configuration can be expected to do. Thus there is literally no way to ship a pre-hardened Kubernetes that has to be softened with a checklist guide. Much of it is about development practices. Kubernetes cannot scan your containers for vulnerabilities and misconfigurations for you. Kubernetes cannot ensure lease privilege practices in your containers for you. Kubernetes cannot do regular reviews of logs and configurations and security patching status for you. Kubernetes cannot monitor audit logs for you. With all this said, it's worth taking a look at the guide. It goes far beyond suggesting a few changes to default settings. Perhaps it could have been better phrased as "Hardening the context and practices around Kubernetes" to avoid this confusion.
- itintheory 4y agoI think this is true, and the issue is deeper for kubernetes. A k8s cluster by itself is not particularly useful. In order to deploy real software you're going to need a bunch of other components, extensions, and software. Things like persistent storage, ingress controllers, service mesh, certificate managers, DNS, etc. All of those components require consideration from a security perspective.
- numbsafari 4y agoEven OpenBSD ships with post-install “hardening” guidance… https://man.openbsd.org/afterboot https://man.openbsd.org/afterboot
- throwaway894345 4y ago> I didn't read this, but ... :)
- stonemetal12 4y agoYeah, but then everybody bitches about ease of use. That other project down the street just works out of the box, while your project is mired in configuration hell. More like we need a better Dev mode vs Production mode switch. Dev mode would be fairly insecure but would also refuse to run on the internet. Production mode would ease deploy but also "self harden".
- Kalium 4y agoThat kind of divide ultimately falls apart. Over time, things built in dev mode rely more and more on its insecurity and production systems get pushed that way. This is why development systems need to be as production-like as possible. Otherwise people ship boring webapps that inexplicable rely on running as root in privileged containers and expect prod to enable this.
- splix 4y agoIs it possible to configure a Kubernetes cluster to run only _signed_ images? I.e., if someone has replaced a Docker in registry is should not be accepted by cluster.
- kryptn 4y agoYou can probably use an Admission Controller with the ImagePolicyWebhook. https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/#imagepolicywebhook https://kubernetes.io/docs/reference/access-authn-authz/admi...
- deleted 4y ago[deleted]
- schainks 4y agoCame here to ask the same thing. If I can sign git commits, can we sign images or even individual layers?
- deleted 4y ago[deleted]
- dilyevsky 4y agoYes, see https://github.com/sigstore/cosign/blob/main/USAGE.md https://github.com/sigstore/cosign/blob/main/USAGE.md for one example
- cheriot 4y agoThere's an ecosystem of policy control tools built on top of k8s' ValidatingWebhooks. Check Open Policy Agent and Kyverno. https://www.openpolicyagent.org/ https://www.openpolicyagent.org/ https://kyverno.io/docs/writing-policies/verify-images/ https://kyverno.io/docs/writing-policies/verify-images/
- mfer 4y agoThe short answer is yes. There are multiple tools that let you do this. My personal favorite tool for this is Kubewarden[1] because its policies are web assembly. There is a specific policy just for verifying signatures[2]. [1] https://www.kubewarden.io/ https://www.kubewarden.io/ [2] https://artifacthub.io/packages/kubewarden/verify-image-signatures/verify-image-signatures https://artifacthub.io/packages/kubewarden/verify-image-sign...
- Havoc 4y agoI find the fact that the Defense dept issues stuff like this almost more interesting than the content itself. Says a lot about what keeps them up at night
- anonporridge 4y agoThe Space Force is cool, but honestly, we desperately need a Cyber Force.
- e12e 4y agohttps://www.cybercom.mil/About/Mission-and-Vision/ https://www.cybercom.mil/About/Mission-and-Vision/ ?
- deleted 4y ago[deleted]
- core-utility 4y agohttps://www.nsa.gov/ https://www.nsa.gov/
- ryanisnan 4y agoYeah but it'd be cool if we had a governmental agency that wasn't adversarial to its own citizens.
- scarby2 4y agoThe nsa is a bit of an oddity. It has conflicting branches within it's own organization. Parts of it want to keep you (and the rest of government) secure and the other parts want backdoors into everything.
- M3L0NM4N 4y agoNo backdoors! Secure everything! Except the stuff we want access to!
- wingmanjd 4y agoAnother guide may be the CIS benchmark guide [1]. I can't attest to efficacy of this particular benchmark from defense.gov (we don't use k8s at $DAYJOB), but we've leveraged other benchmarks from CIS for various flavors of Windows/ Linux. [1] https://www.cisecurity.org/benchmark/kubernetes https://www.cisecurity.org/benchmark/kubernetes
- raesene9 4y agoThis is one of the standards and compliance guides you can use for k8s. The other ones I'm aware of are - CIS Benchmarks, there's coverage for Kubeadm, AKS, EKS, GKE, OpenShift and some others. This is a compliance guide focused on just k8s - DISA STIG for Kubernetes, another compliance guide, they don't mention which distribution but it's kubeadm from looking at the paths mentioned. - PCI Guidance for containers and container orchestration, this one is recent, it's a generic guidance targeted at container environments (docker, k8s etc) for PCI in-scope organizations but TBH it should work for most places (if that one's of interest, some more info https://raesene.github.io/ https://raesene.github.io/) Some more details on these https://www.container-security.site/general_information/container_security_standards.html https://www.container-security.site/general_information/cont... Making security guidance for k8s is kind of tricky due to the number of distros and changes between versions (https://raesene.github.io/blog/2022/09/20/Assessing-Kubernetes-Clusters-for-PCI-Compliance/ https://raesene.github.io/blog/2022/09/20/Assessing-Kubernet...)
- alpb 4y agoPrior discussion: https://news.ycombinator.com/item?id=30692794 https://news.ycombinator.com/item?id=30692794
- jackconsidine 4y ago> Kubernetes, frequently abbreviated “K8s” because there are 8 letters between K and S I'll be damned. I thought it was because the end kind of sounded like "8-es"
- deathanatos 4y agoSame as i18n (internationalization) and l10n (localization).
- cmehdy 4y agoa11y for accessibility also (and perhaps "ally" too?), but is a bit ironic given that screen readers wouldn't be making much sense out of that one.
- paxys 4y agoAnd a16z. It's a pretty common silicon valley convention. I was even asked to implement this in an interview once.
- temp_praneshp 4y agoha, me too, 4-5 years ago!
- M3L0NM4N 4y agoI wish I had that as an interview question.
- Majestic121 4y agoWhat is a16z ? A google search only returns references to Andreessen Horowitz
- bogota 4y agoNot sure if you are joking but that is what it means
- 4y ago
- multani 4y agoFor those who are implementing these security guidelines: how do you ensure they have been correctly implemented? Do you have any kind of static check program that can check beforehand that you are going to deploy a hardened kubernetes cluster? Do you have a "live" checker that can verify the actual configuration of a running cluster? Does it run all the time oronce in a while? Also , if you have an automated way of verifying your configuration, which program do you use? I only know about Chef's Inspec and the CIS profiles that are available online, but the experience wasn't extraordinary and I was wondering what is used in the wild?
- outworlder 4y agoMaybe you can add them to OPA? (https://www.openpolicyagent.org/ https://www.openpolicyagent.org/)
- linuxftw 4y agoThe people that define the standards don't implement them. The people that implement them don't validate them. Government systems don't typically have any kind of system that periodically checks system configuration, though the systems might get reviewed every few years.
- Kalium 4y agoA lot of these things can't be meaningfully statically checked. It has to be done by a working policy apparatus. If your org can't adopt, implement, and adhere to policy then there's no amount of standards documents in the world that will help you much. There's no way in the world to statically and automatically check if your org regularly reviews configurations, responds correctly to monitoring alerts, ensures your developers adhere to least privilege principles, and so on. It has to be policy.
- raesene9 4y agoSo there are various commercial systems that fall under CSPM (or KSPM sometimes) that are designed to assess compliance with different standards. My purely personal opinion on this is that it's difficult to do well as even with compliance standards automating assessment isn't always possible For example the CIS benchmark for k8s can't say "Never use cluster-admin" as there are some legitimate use cases, so instead it says "minimize the use of cluster-admin" which can't be fully automated as a check. To do it well, a company should come up with their own spin on applicable standards, automate where possible (either with 3rd party or internal tooling) and then manually review the things that can't be automated on a periodic bassis (either with internal resource, or consultants)
- gz5 4y agoWell done. From the control plane section: >The Kubernetes API server runs on port 6443, which should be protected by a firewall to accept only expected traffic. How are folks doing this in practice at scale? Managing ACLs for kubectl, admins, workflow systems, distributed worker nodes etc?
- PubliusMI 4y agoThere's actually quite a lot.
- gz5 4y agomeaning lots of ACLs on both sides of the api server, or meaning lots of better (simpler, more secure) ways to do it?
- ly3xqhl8g9 4y agoFor a bare-metal cluster one simple set and forget about it solution is to port forward another external port (e.g., randomish 51203) to the internal control-plane-ip:6443 and block port scan attacks using fail2ban, DenyHosts, psad, etc. This should prevent most of the attacks.
- efortis 4y agoThe example of appendix A is a PoLA violation (Principle of Least Authority). It has source code in the container. Use an external build server.