Description
The IPC namespace contains resources for communication between processes. Sharing it with the host can weaken container isolation. Access to individual IPC resources also depends on user permissions and capabilities.
Application containers do not generally need ipc: "host". Keep container and host IPC namespaces separate unless there is a specific operational requirement.
Potential impact
- The container can access host IPC resources when permissions allow it.
- Reduced isolation can affect other workloads or host resources.
- Exploiting a vulnerability can have a wider impact.
Remediation
- Remove
ipc: "host"and retain default IPC isolation. - Separate debugging or specialized exceptions from production services.
- Review container permissions, namespaces and capabilities together to keep isolation policies consistent.
Examples
Replace sample/app:latest with the actual application image.
Before
yaml
services:
webapp:
image: sample/app:latest
ipc: "host"
After
yaml
services:
webapp:
image: sample/app:latest
Explanation:
- Before: Sharing the host IPC namespace unnecessarily weakens container isolation.
- After: Default IPC separation preserves the boundary between the container and host.