KubeLinter

KubeLinter

Community Analyzer

Container with NET_RAW capability KUBELIN-W1013

Anti-pattern
Major

Indicates when containers do not drop NET_RAW capability

Remediation

NET_RAW makes it so that an application within the container is able to craft raw packets, use raw sockets, and bind to any address. Remove this capability in the containers under containers security contexts.