fix(kubernetes): block kubeconfig command auth bypass (#12091)

Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com>
This commit is contained in:
Hugo Pereira Brito
2026-07-24 08:40:23 +01:00
committed by GitHub
co-authored by Pablo F.G
parent b80e3a7bfb
commit 0b782fcb8c
8 changed files with 125 additions and 20 deletions
@@ -0,0 +1 @@
Kubernetes credential forms now reject kubeconfig files using legacy `auth-provider.config.cmd-path` command authentication
@@ -5,8 +5,8 @@ import { Control, useWatch } from "react-hook-form";
import { WizardTextareaField } from "@/components/providers/workflow/forms/fields";
import { KubernetesCredentials } from "@/types";
import {
KUBECONFIG_EXEC_AUTHENTICATION_ERROR,
kubeconfigContainsExecAuthentication,
KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR,
kubeconfigContainsUnsupportedCommandAuthentication,
} from "@/types/formSchemas";
export const KubernetesCredentialsForm = ({
@@ -18,9 +18,8 @@ export const KubernetesCredentialsForm = ({
control,
name: "kubeconfig_content",
});
const hasExecAuthentication = kubeconfigContainsExecAuthentication(
kubeconfigContent ?? "",
);
const hasUnsupportedCommandAuthentication =
kubeconfigContainsUnsupportedCommandAuthentication(kubeconfigContent ?? "");
return (
<>
@@ -42,9 +41,9 @@ export const KubernetesCredentialsForm = ({
minRows={10}
isRequired
/>
{hasExecAuthentication && (
{hasUnsupportedCommandAuthentication && (
<p className="text-text-error-primary text-xs">
{KUBECONFIG_EXEC_AUTHENTICATION_ERROR}
{KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR}
</p>
)}
</>
+48
View File
@@ -6,6 +6,7 @@ import {
addCredentialsFormSchema,
addCredentialsRoleFormSchema,
addProviderFormSchema,
KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR,
} from "./formSchemas";
const BASE_AWS_ROLE_VALUES = {
@@ -194,10 +195,57 @@ users:
expect(result.error.issues).toContainEqual(
expect.objectContaining({
path: [ProviderCredentialFields.KUBECONFIG_CONTENT],
message: KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR,
}),
);
});
it("reports kubeconfig auth-provider cmd-path on kubeconfig_content field", () => {
const schema = addCredentialsFormSchema("kubernetes");
const result = schema.safeParse({
...BASE_KUBERNETES_VALUES,
[ProviderCredentialFields.KUBECONFIG_CONTENT]: `apiVersion: v1
kind: Config
users:
- name: test-user
user:
auth-provider:
name: gcp
config:
cmd-path: /bin/sh`,
});
expect(result.success).toBe(false);
if (result.success) return;
expect(result.error.issues).toContainEqual(
expect.objectContaining({
path: [ProviderCredentialFields.KUBECONFIG_CONTENT],
message: KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR,
}),
);
});
it("accepts kubeconfig auth-provider without cmd-path", () => {
const schema = addCredentialsFormSchema("kubernetes");
const result = schema.safeParse({
...BASE_KUBERNETES_VALUES,
[ProviderCredentialFields.KUBECONFIG_CONTENT]: `apiVersion: v1
kind: Config
users:
- name: test-user
user:
auth-provider:
name: oidc
config:
client-id: prowler`,
});
expect(result.success).toBe(true);
});
it("accepts malformed kubeconfig content for backend validation", () => {
const schema = addCredentialsFormSchema("kubernetes");
+19 -6
View File
@@ -6,14 +6,14 @@ import { validateMutelistYaml, validateYaml } from "@/lib/yaml";
import { PROVIDER_TYPES, ProviderType } from "./providers";
export const KUBECONFIG_EXEC_AUTHENTICATION_ERROR =
"Kubernetes kubeconfig exec authentication is not supported in Prowler Cloud for security reasons.";
export const KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR =
"Kubernetes kubeconfig command-based authentication is not supported in Prowler Cloud for security reasons.";
const isRecord = (value: unknown): value is Record<string, unknown> => {
return typeof value === "object" && value !== null && !Array.isArray(value);
};
export const kubeconfigContainsExecAuthentication = (
export const kubeconfigContainsUnsupportedCommandAuthentication = (
value: string,
): boolean => {
try {
@@ -28,7 +28,16 @@ export const kubeconfigContainsExecAuthentication = (
return false;
}
return "exec" in userEntry.user;
if ("exec" in userEntry.user) {
return true;
}
const authProvider = userEntry.user["auth-provider"];
if (!isRecord(authProvider) || !isRecord(authProvider.config)) {
return false;
}
return "cmd-path" in authProvider.config;
});
} catch {
return false;
@@ -229,9 +238,13 @@ export const addCredentialsFormSchema = (
.string()
.min(1, "Kubeconfig Content is required")
.refine(
(value) => !kubeconfigContainsExecAuthentication(value),
(value) =>
!kubeconfigContainsUnsupportedCommandAuthentication(
value,
),
{
error: KUBECONFIG_EXEC_AUTHENTICATION_ERROR,
error:
KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR,
},
),
}