Kubernetes container runs in privileged mode

Privileged Kubernetes containers weaken isolation by allowing broad access to node resources.

Description

Container-level securityContext.privileged: true relaxes normal security restrictions and permits broad host access. On Linux, it grants all capabilities and can bypass protections such as seccomp and AppArmor.

Avoid privileged mode for ordinary applications. If a system task requires it, separate that workload and tightly restrict access.

Potential impact

  • The container can gain excessive access to node devices and kernel functionality.
  • One compromised application can affect the node and other workloads.

Remediation

  • Remove securityContext.privileged or set it to false.
  • Where possible, grant only the narrow capabilities and device access required.
  • Review hostPath, hostNetwork and added capabilities. Apply restrictions to the workload template and test required functionality.

Examples

The two Pods illustrate the setting. Apply it to the actual image and workload template used by your deployment.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: privileged-pod
spec:
  containers:
    - name: app
      image: gcr.io/google-samples/node-hello:1.0
      securityContext:
        privileged: true

The container runs in privileged mode.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: standard-pod
spec:
  containers:
    - name: app
      image: gcr.io/google-samples/node-hello:1.0
      securityContext:
        privileged: false

Privileged mode is disabled. The runtime user and other permissions still need separate restrictions.

References