Skip to content

Commit

Permalink
feat: check non-zero runAsUser in M-113
Browse files Browse the repository at this point in the history
  • Loading branch information
matheusfm committed Mar 13, 2024
1 parent d81464c commit 14d6a98
Show file tree
Hide file tree
Showing 2 changed files with 44 additions and 2 deletions.
14 changes: 12 additions & 2 deletions internal/builtins/pss/restricted/M-113_run_as_non_root.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,21 +43,31 @@ match:
version: v1
resource: jobs
variables:
# pod-level runAsNonRoot is explicitly set to true
- name: podRunAsNonRoot
expression: podSpec.?securityContext.?runAsNonRoot.orValue(false)

# pod-level runAsUser is explicitly set to non-zero
- name: podRunAsNonZeroUser
expression: podSpec.?securityContext.?runAsUser.orValue(0) != 0

# containers that explicitly set runAsNonRoot=false
- name: explicitlyBadContainers
expression: >
allContainers.filter(c,
has(c.securityContext) && has(c.securityContext.runAsNonRoot) && c.securityContext.runAsNonRoot == false
)
# containers that didn't set runAsNonRoot and aren't caught by a pod-level runAsNonRoot=true
# containers that
# - didn't set runAsNonRoot
# - aren't caught by a pod-level runAsNonRoot=true
# - didn't set non-zero runAsUser
# - aren't caught by a pod-level non-zero runAsUser
- name: implicitlyBadContainers
expression: >
allContainers.filter(c,
!variables.podRunAsNonRoot && (!has(c.securityContext) || !has(c.securityContext.runAsNonRoot))
(!variables.podRunAsNonRoot && (!has(c.securityContext) || !has(c.securityContext.runAsNonRoot))) &&
(!variables.podRunAsNonZeroUser && c.?securityContext.?runAsUser.orValue(0) == 0)
)
validations:
Expand Down
32 changes: 32 additions & 0 deletions internal/builtins/pss/restricted/M-113_run_as_non_root_test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -151,3 +151,35 @@
selector:
matchLabels:
app: nginx
- name: "Pod set runAsUser to non-zero"
pass: true
input: |
apiVersion: v1
kind: Pod
metadata:
name: nginx
labels:
app: nginx
spec:
securityContext:
runAsUser: 1
containers:
- name: nginx
image: nginx
- name: "container set runAsUser to non-zero"
pass: true
input: |
apiVersion: v1
kind: Pod
metadata:
name: nginx
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx
securityContext:
runAsUser: 1

0 comments on commit 14d6a98

Please sign in to comment.