Shared host network namespace

Review the need for host networking and expose only required addresses and ports.

Description

With network_mode: "host", the container uses the host network rather than a separate network namespace. This applies in environments that support host networking; actual external access also depends on listening addresses, firewall rules and authentication.

Host networking can cause port conflicts, broader exposure and weaker network isolation. General application containers should retain separate networking unless they have a specific need for host networking.

Potential impact

  • The container and host share the same network namespace.
  • Managing exposed ports and port conflicts can become more difficult.
  • Reduced network isolation can broaden the attack surface.

Remediation

  • Remove network_mode: "host" and use the default bridge network or a dedicated network.
  • When external access is needed, bind only the required host addresses and ports. Communication within a Compose network does not require published ports.
  • Keep workloads that require host networking in a separate exception configuration.

Examples

Before

yaml
services:
  mongo:
    image: mongo:latest
    network_mode: "host"

After

yaml
services:
  mongo:
    image: mongo:latest
    ports:
      - "27017:27017"

Explanation:

  • Before: Sharing the host network weakens isolation and makes the container use the host’s port space.
  • After: The container retains separate networking and publishes a port. 27017:27017 binds to all host interfaces by default, so restrict the listening address and firewall rules as needed and configure MongoDB authentication separately.

References