Description
Mounting a hostPath volume into a container provides direct access to the node filesystem. Avoid this for ordinary applications unless node access is essential, as it can be for a system agent; use storage suited to the application instead.
Moving a workload to kube-system does not restrict its file access. The risk depends on the actual host path, container mount settings, and file permissions.
Potential impact
- Node configuration, logs, or credentials may become accessible to the container.
- Write access can allow changes to host files that affect other workloads or node operation.
- Dependence on node-local files can cause workloads to behave differently across nodes.
Remediation
- Consider a PVC backed by suitable storage for application data, ConfigMaps for configuration, and Secrets for sensitive values.
- Limit necessary host paths to essential system workloads, and set
readOnly: truewhen only reading is required. - Restrict who can create or modify those workloads. Do not rely on a namespace name as the security boundary.
Examples
These excerpts show volume declarations. Selectors, Pod labels, and volumeMounts are omitted. Supply the required fields and supported images for actual use.
Before
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deployment
namespace: default
spec:
template:
spec:
containers:
- name: nginx
image: nginx:1.14.2
volumes:
- name: static-page-dir
hostPath:
path: /var/local/static
type: DirectoryOrCreate
This configuration provides the host directory /var/local/static to an ordinary application. Mounting the volume makes the application dependent on files on the node.
After
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: fluentd-elasticsearch
namespace: kube-system
spec:
template:
spec:
containers:
- name: fluentd-elasticsearch
image: quay.io/fluentd_elasticsearch/fluentd:v2.5.2
volumes:
- name: varlog
hostPath:
path: /var/log
Access to /var/log can be legitimate for a system log collector. Placement in kube-system does not provide protection by itself; make the actual volumeMounts read-only and review access to the logs.