Chuyển đến nội dung chính

Bài 4: RBAC & Kubernetes Security

Role-Based Access Control (RBAC), ServiceAccounts, Network Policies, Pod Security Standards và Security Context. Bảo mật Kubernetes cluster.

RBAC Authorization Model — Subject, RoleBinding, Role, Rules

1. RBAC — Role-Based Access Control

RBAC kiểm soát ai (User, Group, ServiceAccount) được làm gì (verbs) với tài nguyên nào (resources) trong namespace hoặc cluster.

RBAC Flow:
Subject (Who?)    →    Role/ClusterRole (What?)    →    RoleBinding (Links)

  User "alice"          Role "pod-reader"              RoleBinding
  ServiceAccount        - get pods                     alice → pod-reader
  Group "devs"          - list pods                    (in namespace "dev")
                        - watch pods
ObjectScopeDùng khi
RoleNamespaceQuyền trong 1 namespace
ClusterRoleCluster-wideQuyền trên toàn cluster hoặc non-namespaced resources (nodes)
RoleBindingNamespaceGán Role or ClusterRole cho Subject trong 1 namespace
ClusterRoleBindingCluster-wideGán ClusterRole cho Subject trên toàn cluster

Exam tip: Có thể dùng RoleBinding để gán ClusterRole vào 1 namespace cụ thể — đây là cách tái sử dụng permission template mà không cấp quyền toàn cluster. Rất hay xuất hiện trong exam!

2. ServiceAccounts

Mỗi Pod có thể gắn một ServiceAccount. Token của ServiceAccount được mount tự động vào /var/run/secrets/kubernetes.io/serviceaccount/. Pods dùng token này để gọi Kubernetes API.

Default ServiceAccount flow:
  Pod → ServiceAccount → RBAC Role → API Server

Ví dụ: Prometheus cần đọc Pod metrics:
  ServiceAccount: prometheus-sa
  ClusterRole: pod-metrics-reader (verbs: get, list, watch)
  ClusterRoleBinding: prometheus-sa → pod-metrics-reader

3. Network Policies

Mặc định, tất cả Pods trong cluster có thể communicate với nhau. NetworkPolicy cho phép giới hạn traffic ingress/egress dựa trên Pod selector, namespace selector, hoặc IP block.

❌ Default (no NetworkPolicy): All pods talk to all pods
✅ With NetworkPolicy:
   frontend → backend (allowed)
   frontend → database (BLOCKED)
   backend → database (allowed)

Exam tip: NetworkPolicy chỉ có tác dụng khi CNI plugin hỗ trợ (Calico, Cilium, Weave). Flannel không hỗ trợ NetworkPolicy. Nếu không có policy nào → allow all. Nếu có ít nhất 1 policy → default deny cho traffic được select.

4. Pod Security Standards

Kubernetes định nghĩa 3 Pod Security Standards (thay thế PodSecurityPolicy từ v1.25):

ProfileMức độ hạn chếDùng cho
PrivilegedKhông hạn chếSystem/infra workloads (kube-system)
BaselineNgăn escalation rõ ràngWorkloads thông thường
RestrictedTuân thủ hardening tối đaSecurity-sensitive apps

5. SecurityContext

SecurityContext cấu hình bảo mật ở cấp Pod hoặc Container:

Security settingÝ nghĩa
runAsNonRoot: trueContainer không được chạy với UID 0
runAsUser: 1000Chạy container với UID 1000
readOnlyRootFilesystem: trueFilesystem read-only (write phải dùng volume)
allowPrivilegeEscalation: falseKhông cho process leo thang đặc quyền
capabilities.drop: ["ALL"]Bỏ tất cả Linux capabilities

6. Cheat Sheet

Câu hỏi examĐáp án
Pod cần gọi K8s API, dùng gì?ServiceAccount
Giới hạn quyền user trong 1 namespace?Role + RoleBinding
Giới hạn network traffic giữa Pods?NetworkPolicy
NetworkPolicy cần gì để hoạt động?CNI plugin hỗ trợ (Calico, Cilium)
Privileged → Restricted, Pod Security cần?Pod Security Admission

7. Practice Questions

Q1: An application Pod needs to access the Kubernetes API to list Pods in its own namespace. What should a cluster administrator create?

  • A) ClusterRole with ClusterRoleBinding for all namespaces
  • B) ServiceAccount with Role (list pods) and RoleBinding ✓
  • C) Service with type LoadBalancer for API Server
  • D) ConfigMap with API Server credentials

Explanation: The Pod needs a ServiceAccount, a Role granting "list pods" in its namespace, and a RoleBinding linking them. Using ClusterRole would over-grant access across all namespaces.

Q2: A NetworkPolicy is applied to a Pod. What is the default behavior for traffic not explicitly matched by any rule?

  • A) All traffic is allowed (default allow)
  • B) Traffic is logged but not blocked
  • C) Traffic that matches the Pod selector is denied; all other traffic passes ✓
  • D) All traffic to/from the Pod is denied

Explanation: Once a NetworkPolicy selects a Pod (via podSelector), all traffic not explicitly allowed is denied for that policy type (ingress/egress). Non-selected Pods remain unaffected and have full connectivity.

Q3: Which Pod Security Standard profile should be used for a system-level component that requires privileged access to the host?

  • A) Restricted
  • B) Baseline
  • C) Privileged ✓
  • D) SystemAdmin

Explanation: The Privileged profile places no restrictions on Pods, allowing all capabilities. It's intended for system/infrastructure components. Baseline prevents known privilege escalations; Restricted enforces maximum hardening.