{"id":1898,"date":"2017-02-09T22:35:38","date_gmt":"2017-02-10T03:35:38","guid":{"rendered":"http:\/\/blog.domb.net\/?p=1898"},"modified":"2017-05-17T10:38:03","modified_gmt":"2017-05-17T14:38:03","slug":"deny-container-image-execution-via-cloudforms-4-2-openshift-3-4","status":"publish","type":"post","link":"https:\/\/blog.domb.net\/?p=1898","title":{"rendered":"Deny container image execution via CloudForms 4.2 \/ OpenShift 3.4"},"content":{"rendered":"<p>I&#8217;ve been waiting for this feature since quite a while and its finally here and working. CloudForms 4.2 and OpenShift 3.4 have the ability combined of scanning docker images and define if the images are compliant or not. If the image is not compliant CloudForms annotates the image in OpenShift with <strong>images.openshift.io\/deny-execution: true<\/strong> and if OpenShift is configured correctly it will <strong>deny<\/strong> execution the next time someone tries to run\u00a0the container image.<\/p>\n<p>Having this feature is really awesome as you can prevent someone from building a vulnerable image and deploying it multiple times. Also CloudForms can either have a policy set on the provider which auto scans newly discovered pods\/images, schedule image registry scans or your check images on demand.<\/p>\n<p>So here are the steps to get this working (a detailed description on what an image policy is can be found here: https:\/\/docs.openshift.com\/container-platform\/3.4\/admin_guide\/image_policy.html)<\/p>\n<p><strong>1.<\/strong> First \u00a0login to\u00a0the OpenShift Master and edit \/etc\/origin\/master\/master-config.yaml Add the following lines above apiLevels<\/p>\n<pre class=\"lang:python decode:true \" title=\"Image and registry policies\">admissionConfig:\r\n  pluginConfig:\r\n    openshift.io\/ImagePolicy:\r\n      configuration:\r\n        kind: ImagePolicyConfig\r\n        apiVersion: v1\r\n        resolveImages: AttemptRewrite\r\n        executionRules:\r\n        - name: execution-denied\r\n          onResources:\r\n          - resource: pods\r\n          reject: true\r\n          matchImageAnnotations:\r\n          - key: images.openshift.io\/deny-execution\r\n            value: \"true\"\r\n          skipOnResolutionFailure: true\r\n        - name: allow-images-from-internal-registry\r\n          onResources:\r\n          - resource: pods\r\n          - resource: builds\r\n          matchIntegratedRegistry: false\r\n        - name: allow-images-from-dockerhub\r\n          onResources:\r\n          - resource: pods\r\n          - resource: builds\r\n          matchRegistries:\r\n          - docker.io\r\n<\/pre>\n<p><strong>2.<\/strong> Restart the OpenShift masters\u00a0so that the policy will take effect.<\/p>\n<pre class=\"lang:default decode:true \">[ldomb@osemaster ~]$ sudo systemctl restart atomic-openshift-master.service\r\n[ldomb@osemaster ~]$ sudo systemctl restart atomic-openshift-node.service<\/pre>\n<p><strong>3.<\/strong> Deploy a vulnerable image in OpenShift. In my case I named it testme.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1914\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.18.31-PM.png\" alt=\"\" width=\"643\" height=\"254\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.18.31-PM.png 643w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.18.31-PM-300x119.png 300w\" sizes=\"auto, (max-width: 643px) 100vw, 643px\" \/><\/p>\n<p><strong>4.<\/strong> Go to CloudForms and run a Smart State Analysis. Login to CloudForms and go to Compute -&gt; Containers -&gt; Container Images and choose the image you&#8217;ve just deployed via OpenShift.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1900\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.39.10-PM.png\" alt=\"\" width=\"1048\" height=\"80\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.39.10-PM.png 1048w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.39.10-PM-300x23.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.39.10-PM-768x59.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.39.10-PM-1024x78.png 1024w\" sizes=\"auto, (max-width: 1048px) 100vw, 1048px\" \/><\/p>\n<p><strong>5.<\/strong> Click on the image. \u00a0Then on the top left press &#8220;Perform Smart StateAnalysis&#8221;<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1901\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.40.44-PM.png\" alt=\"\" width=\"715\" height=\"128\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.40.44-PM.png 715w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.40.44-PM-300x54.png 300w\" sizes=\"auto, (max-width: 715px) 100vw, 715px\" \/><\/p>\n<p><strong>6.<\/strong> If your admin in OpenShift you can go to the management-infra project and see that a new pod manageiq-img-scan is started (oc get pods). The image will pull your testme image down and check it for vulnerabilities. Once scanned (remember we did not add any policies yet) you will see the following:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1902\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.09-PM.png\" alt=\"\" width=\"367\" height=\"103\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.09-PM.png 367w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.09-PM-300x84.png 300w\" sizes=\"auto, (max-width: 367px) 100vw, 367px\" \/><\/p>\n<p><strong>7.<\/strong>\u00a0Go to policy -&gt; manage policy <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1903\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.40-PM.png\" alt=\"\" width=\"129\" height=\"72\" \/>and check the box for OpenScap Profile <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1905\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.53-PM.png\" alt=\"\" width=\"434\" height=\"121\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.53-PM.png 434w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.43.53-PM-300x84.png 300w\" sizes=\"auto, (max-width: 434px) 100vw, 434px\" \/> Once checked go back to the policies and run &#8220;Check Compliance of last known configuration.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1904\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.44.10-PM.png\" alt=\"\" width=\"254\" height=\"104\" \/><\/p>\n<p><strong>8.<\/strong> As I used a image which has known vulnerabilities the compliance status will show Non-Compliant.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1910\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.44.15-PM.png\" alt=\"\" width=\"523\" height=\"93\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.44.15-PM.png 523w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.44.15-PM-300x53.png 300w\" sizes=\"auto, (max-width: 523px) 100vw, 523px\" \/> What happens in the background as well is that CloudForms tells OpenShift to annotate the image with <strong>images.openshift.io\/deny-execution: true<\/strong><\/p>\n<p><strong>9.<\/strong> Go to your image id and copy your sha<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1911\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.54.25-PM.png\" alt=\"\" width=\"510\" height=\"184\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.54.25-PM.png 510w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-9.54.25-PM-300x108.png 300w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><\/p>\n<p><strong>10.<\/strong> Now in OpenShift\u00a0check if the annotation exist. You can either check in the UI in OpenShift under image -&gt; annotations or on the command line<\/p>\n<pre class=\"lang:default decode:true \">[ldomb@osemaster ~]$ oc describe image sha256:04bbe933626ad63ccb2bffeecdfe64cdb9da68a67ebc037976f5c6efc810bc25\r\n....\r\nAnnotations: images.openshift.io\/deny-execution=true\r\nopenshift.io\/image.managed=true\r\nsecurity.manageiq.org\/failed-policy=openscap policy\r\n....<\/pre>\n<p><strong>11.<\/strong>\u00a0Lets see if the policy catches and\u00a0build a new container based of the above. As you can see below OpenShift denies running the above image!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1912\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.01.20-PM.png\" alt=\"\" width=\"1167\" height=\"592\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.01.20-PM.png 1167w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.01.20-PM-300x152.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.01.20-PM-768x390.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2017-02-09-at-10.01.20-PM-1024x519.png 1024w\" sizes=\"auto, (max-width: 1167px) 100vw, 1167px\" \/><\/p>\n<p><strong>12.<\/strong> If you want to remove the restriction your can use<\/p>\n<pre class=\"lang:default decode:true \">[ldomb@osemaster ~]$ oc annotate --overwrite image sha256:04bbe933626ad63ccb2bffeecdfe64cdb9da68a67ebc037976f5c6efc810bc25 images.openshift.io\/deny-execution=false<\/pre>\n<p>Happy OpenShifting<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve been waiting for this feature since quite a while and its finally here and working. CloudForms 4.2 and OpenShift 3.4 have the ability combined of scanning docker images and define if the images are compliant or not. If the image is not compliant CloudForms annotates the image in OpenShift with images.openshift.io\/deny-execution: true and if&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2025,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[76],"tags":[42,29,83,55,84],"class_list":["post-1898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-openshift","tag-cloud","tag-cloudforms","tag-deny-container-execution","tag-openshift","tag-vulnerabilites"],"_links":{"self":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/1898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1898"}],"version-history":[{"count":14,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/1898\/revisions"}],"predecessor-version":[{"id":2029,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/1898\/revisions\/2029"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/media\/2025"}],"wp:attachment":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}