> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Ensure Seccomp Profile Is Set Docker/Default In Your Pod Definitions

### More Info:

Enable docker/default seccomp profile in your pod definitions

### Risk Level

High

### Address

Security

### Compliance Standards

* CIS GKE

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. **Identify pods to review (any machine with kubectl access)**\
           Use label/namespace filters as appropriate; to start with everything:
           ```bash theme={null}
           kubectl get pods --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}{" "}{.metadata.name}{" "}{.metadata.annotations.seccomp\.security\.alpha\.kubernetes\.io/pod}{"\n"}{end}' | sort
           ```
           This lists each pod and its pod-level seccomp annotation (if any). Note pods missing `docker/default`.

        2. **Check container-level seccomp annotations (any machine with kubectl access)**\
           For pods you are reviewing, inspect full annotations to see container-specific overrides:
           ```bash theme={null}
           kubectl get pod <pod-name> -n <namespace> -o yaml | grep -A3 'seccomp.security.alpha.kubernetes.io'
           ```
           Determine whether each container is using `docker/default`, another profile (e.g. `unconfined`), or none.

        3. **Decide policy exceptions (any machine with kubectl access)**\
           With security and application owners, decide:
           * Which namespaces/workloads must use `docker/default`
           * Which, if any, need a different profile or `unconfined` for functional reasons\
             Document approved exceptions before changing manifests.

        4. **Update workload manifests to set `docker/default` (any machine with kubectl access)**\
           For non-exempt workloads managed via manifests/Helm/Kustomize, edit the source manifests, not live objects. Add either pod-level or container-level annotations, for example:
           * Pod-level:
             ```yaml theme={null}
             metadata:
               annotations:
                 seccomp.security.alpha.kubernetes.io/pod: docker/default
             ```
           * Container-level (per-container override):
             ```yaml theme={null}
             metadata:
               annotations:
                 seccomp.security.alpha.kubernetes.io/<container-name>: docker/default
             ```
           Apply via your normal deployment pipeline (e.g., `kubectl apply -f <file>`, `helm upgrade`, or GitOps).

        5. **Re‑deploy or roll pods so new annotations take effect (any machine with kubectl access)**\
           After manifest changes, ensure pods are recreated:
           * For Deployments/DaemonSets/StatefulSets: rely on rolling updates from the apply/upgrade, or trigger:
             ```bash theme={null}
             kubectl rollout restart deployment/<deployment-name> -n <namespace>
             ```
           * For static or singleton pods created manually, delete and recreate from the updated manifest:
             ```bash theme={null}
             kubectl delete -f <updated-manifest>.yaml
             kubectl apply -f <updated-manifest>.yaml
             ```

        6. **Verify effective configuration (any machine with kubectl access)**\
           Re-run a cluster-wide check to confirm pods now have `docker/default` configured where required:
           ```bash theme={null}
           kubectl get pods --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}{" "}{.metadata.name}{" "}{.metadata.annotations.seccomp\.security\.alpha\.kubernetes\.io/pod}{"\n"}{end}' | sort
           ```
           For spot checks, validate specific pods:
           ```bash theme={null}
           kubectl get pod <pod-name> -n <namespace> -o yaml | grep -A3 'seccomp.security.alpha.kubernetes.io'
           ```
           Confirm that annotations match your policy decisions (`docker/default` or documented exceptions).
      </Accordion>

      <Accordion title="Using kubectl">
        On any machine with kubectl access:

        1. List all pods and their seccomp-related annotations

        ```bash theme={null}
        kubectl get pods -A \
          -o custom-columns='NAMESPACE:.metadata.namespace,NAME:.metadata.name,SECCOMP_POD:.metadata.annotations.seccomp\.security\.alpha\.kubernetes\.io/pod,SECCOMP_CONTAINER:.metadata.annotations.seccomp\.security\.alpha\.kubernetes\.io/container\.default'
        ```

        Problem indication:

        * `SECCOMP_POD` is empty/`<none>` and
        * `SECCOMP_CONTAINER` is empty/`<none>`
          for pods that you expect to be constrained.

        2. Inspect annotations on a specific pod

        ```bash theme={null}
        kubectl get pod <pod-name> -n <namespace> -o yaml | grep -A5 "annotations:"
        ```

        Problem indication:

        * Missing `seccomp.security.alpha.kubernetes.io/pod: docker/default`
        * Or present but set to anything other than `docker/default`.

        3. See pods that have any seccomp alpha annotation (to focus review)

        ```bash theme={null}
        kubectl get pods -A -o json | jq -r '
          .items[] |
          select(.metadata.annotations |
            has("seccomp.security.alpha.kubernetes.io/pod") or
            has("seccomp.security.alpha.kubernetes.io/container.default")) |
          [.metadata.namespace, .metadata.name,
           .metadata.annotations["seccomp.security.alpha.kubernetes.io/pod"],
           .metadata.annotations["seccomp.security.alpha.kubernetes.io/container.default"]] |
          @tsv'
        ```

        Problem indication:

        * Annotations present but value not `docker/default`, if your policy is to use `docker/default`.

        4. Confirm api-server alpha feature gate status (to see if the annotation can even work)

        If the control plane is exposed as a pod (typical managed GKE):

        ```bash theme={null}
        kubectl -n kube-system get pods -l component=kube-apiserver -o yaml | grep -A2 "\-\-feature-gates"
        ```

        Problem indication:

        * `--feature-gates` does not include `AllAlpha=true` (per the benchmark’s remediation requirement for this check).
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        # Report pods that are NOT using the docker/default seccomp profile at pod scope
        # Run on: any machine with kubectl access and current context set

        set -euo pipefail

        echo "Cluster-wide seccomp (pod-level) report - pods missing 'docker/default'"
        echo "Context: $(kubectl config current-context)"
        echo

        # 1) List all pods with their pod-level seccomp annotation
        echo "== Raw pod-level seccomp annotations =="
        kubectl get pods -A -o=jsonpath='{range .items[*]}{.metadata.namespace}{"\t"}{.metadata.name}{"\t"}{.metadata.annotations.seccomp\.security\.alpha\.kubernetes\.io/pod}{"\n"}{end}' \
          | sort
        echo

        # 2) Show only pods that are missing or not set to docker/default
        echo "== Pods MISSING pod-level 'docker/default' seccomp profile =="
        echo "# Columns: NAMESPACE  POD  POD_SECCOMP_ANNOTATION"
        kubectl get pods -A -o=jsonpath='{range .items[*]}{.metadata.namespace}{"\t"}{.metadata.name}{"\t"}{.metadata.annotations.seccomp\.security\.alpha\.kubernetes\.io/pod}{"\n"}{end}' \
          | awk -F'\t' '
            {
              ns=$1; pod=$2; ann=$3;
              # Treat literal "null" or empty as unset
              if (ann == "" || ann == "null" || ann != "docker/default") {
                print ns "\t" pod "\t" (ann == "" || ann == "null" ? "<unset>" : ann);
              }
            }
          ' \
          | sort
        echo

        cat <<'EOF'
        INTERPRETING THE OUTPUT
        -----------------------
        - The "Raw pod-level seccomp annotations" section shows the exact current value of
          metadata.annotations["seccomp.security.alpha.kubernetes.io/pod"] for every pod.

        - In "Pods MISSING pod-level 'docker/default' seccomp profile":
          * Any line with third column "<unset>" means the pod has NO pod-level seccomp
            annotation configured.
          * Any line where the third column is NOT "docker/default" (e.g. "unconfined"
            or some other value) means the pod does not meet the benchmark expectation.

        These pods should be reviewed manually. For pods that should comply with CISGKE 4.6.2,
        update their manifests (Deployments, DaemonSets, etc.) to include:
          metadata:
            annotations:
              seccomp.security.alpha.kubernetes.io/pod: docker/default
        EOF
        ```
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>

### Additional Reading:

* [https://kubernetes.io/docs/tutorials/clusters/seccomp/](https://kubernetes.io/docs/tutorials/clusters/seccomp/)
