Shared host PID namespace

Remove unnecessary host PID sharing and preserve process isolation.

Description

Using pid: "host" makes host process information more directly visible inside the container and reduces its default isolation.

Visibility does not automatically grant control over a process; user permissions and capabilities still apply. General application containers should remain separate from the host process namespace. Avoid host PID sharing unless it is required for debugging or a specialized tool.

Potential impact

  • The container can observe more information about host processes.
  • Reduced isolation can increase the effects on host resources and other workloads.
  • Exploiting a vulnerability may have a wider impact on the host.

Remediation

  • Remove pid: "host" and retain the default namespace isolation.
  • Keep necessary exceptions in a separate debugging configuration instead of applying them to production services.
  • Review container permissions, capabilities and mounts together with namespace isolation.

Examples

Replace sample/app:latest with the actual application image.

Before

yaml
services:
  service_name_1:
    image: sample/app:latest
    pid: "host"

After

yaml
services:
  service_name_1:
    image: sample/app:latest

Explanation:

  • Before: Sharing the host PID namespace reduces container isolation.
  • After: The container retains the default separation from the host process namespace.

References