Description
Using pid: "host" makes host process information more directly visible inside the container and reduces its default isolation.
Visibility does not automatically grant control over a process; user permissions and capabilities still apply. General application containers should remain separate from the host process namespace. Avoid host PID sharing unless it is required for debugging or a specialized tool.
Potential impact
- The container can observe more information about host processes.
- Reduced isolation can increase the effects on host resources and other workloads.
- Exploiting a vulnerability may have a wider impact on the host.
Remediation
- Remove
pid: "host"and retain the default namespace isolation. - Keep necessary exceptions in a separate debugging configuration instead of applying them to production services.
- Review container permissions, capabilities and mounts together with namespace isolation.
Examples
Replace sample/app:latest with the actual application image.
Before
yaml
services:
service_name_1:
image: sample/app:latest
pid: "host"
After
yaml
services:
service_name_1:
image: sample/app:latest
Explanation:
- Before: Sharing the host PID namespace reduces container isolation.
- After: The container retains the default separation from the host process namespace.