Skip to content

Add application-controlled security policies for kubeconfig exec plugins - #1930

Draft
brendandburns with Copilot wants to merge 3 commits into
masterfrom
copilot/add-security-policy-support
Draft

brendandburns with Copilot wants to merge 3 commits into
masterfrom
copilot/add-security-policy-support

Conversation

Copilot AI commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Untrusted kubeconfigs can launch arbitrary local processes through exec credential plugins. This adds application-controlled authorization without requiring callers to parse and inspect kubeconfig themselves.

  • Policy API: Immutable AllowAll (default), DenyAll, and Allowlist policies across configuration builders, including Classic and AOT. Existing API signatures remain available.
  • Enforcement: Checks initial execution and token refresh before process launch. Denials throw ExecCredentialPluginDeniedException; kubeconfig cannot override the application policy.
  • Allowlist semantics: Match basenames or exact absolute paths, including Windows UNC paths. Empty lists deny all; invalid entries and quoted commands are rejected. Allowlist mode also rejects kubeconfig-supplied environment overrides to prevent command redirection and loader injection.
  • Trust boundaries: Basenames permit any matching executable location. Arguments and executable contents are not restricted; the policy is not a sandbox.
var config = KubernetesClientConfiguration.BuildConfigFromConfigFile(
    kubeConfigPath,
    execCredentialPluginPolicy: ExecCredentialPluginPolicy.DenyAll);

// Or explicitly approve credential plugins:
var config = KubernetesClientConfiguration.BuildConfigFromConfigFile(
    kubeConfigPath,
    execCredentialPluginPolicy: ExecCredentialPluginPolicy.Allowlist(
        "kubelogin",
        @"C:\Program Files\Contoso\trusted-plugin.exe"));

Copilot AI balanced review requested due to automatic review settings October 6, 2026 21:51
@kubernetes-prow kubernetes-prow Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Oct 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

@linux-foundation-easycla

linux-foundation-easycla Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

CLA Not Signed

@kubernetes-prow kubernetes-prow Bot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Oct 6, 2026
Copilot AI linked an issue Oct 6, 2026 that may be closed by this pull request
Co-authored-by: brendandburns <5751682+brendandburns@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:01
@kubernetes-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Copilot
Once this PR has been reviewed and has the lgtm label, please ask for approval from brendandburns. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Oct 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Kubeconfig-controlled environment variables can bypass allowlisted command restrictions and still enable arbitrary code execution.

Review effort: Balanced
Findings: 1 High severity

Open (1)

Comment on lines +77 to +78
return commands.Any(entry => string.Equals(
entry, IsBasename(entry) ? Path.GetFileName(command) : command, CommandComparison));

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in the latest commit: Allowlist mode now rejects all kubeconfig-supplied environment overrides before process creation and again at the launch boundary; AllowAll retains existing behavior. Tests cover PATH, LD_PRELOAD, DYLD_INSERT_LIBRARIES, and ordinary overrides during configuration loading, direct execution, and refresh. Documentation explains trusted application-inherited environment settings, basename resolution limitations, and that approved plugin arguments/executable behavior are not sandboxed.

Co-authored-by: brendandburns <5751682+brendandburns@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-sensitive process execution changes span multiple target variants, while the PR explicitly indicates build and security validation remain incomplete.

Review effort: Balanced
Findings: 1 High severity

Open (1)

Copilot AI changed the title [WIP] Add security policy support for kubeconfig exec credential plugins Add application-controlled security policies for kubeconfig exec plugins Oct 6, 2026
Copilot AI requested a review from brendandburns October 6, 2026 22:28

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. size/XL Denotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add security policy support for kubeconfig exec credential plugins

3 participants