Shared host IPC namespace

Remove unnecessary host IPC sharing and isolate interprocess communication resources.

Description

The IPC namespace contains resources for communication between processes. Sharing it with the host can weaken container isolation. Access to individual IPC resources also depends on user permissions and capabilities.

Application containers do not generally need ipc: "host". Keep container and host IPC namespaces separate unless there is a specific operational requirement.

Potential impact

  • The container can access host IPC resources when permissions allow it.
  • Reduced isolation can affect other workloads or host resources.
  • Exploiting a vulnerability can have a wider impact.

Remediation

  • Remove ipc: "host" and retain default IPC isolation.
  • Separate debugging or specialized exceptions from production services.
  • Review container permissions, namespaces and capabilities together to keep isolation policies consistent.

Examples

Replace sample/app:latest with the actual application image.

Before

yaml
services:
  webapp:
    image: sample/app:latest
    ipc: "host"

After

yaml
services:
  webapp:
    image: sample/app:latest

Explanation:

  • Before: Sharing the host IPC namespace unnecessarily weakens container isolation.
  • After: Default IPC separation preserves the boundary between the container and host.

References