Workload outside kube-system uses hostPath

Using hostPath for ordinary applications broadens access to node files and requires strict limits on need and permissions.

Description

Mounting a hostPath volume into a container provides direct access to the node filesystem. Avoid this for ordinary applications unless node access is essential, as it can be for a system agent; use storage suited to the application instead.

Moving a workload to kube-system does not restrict its file access. The risk depends on the actual host path, container mount settings, and file permissions.

Potential impact

  • Node configuration, logs, or credentials may become accessible to the container.
  • Write access can allow changes to host files that affect other workloads or node operation.
  • Dependence on node-local files can cause workloads to behave differently across nodes.

Remediation

  • Consider a PVC backed by suitable storage for application data, ConfigMaps for configuration, and Secrets for sensitive values.
  • Limit necessary host paths to essential system workloads, and set readOnly: true when only reading is required.
  • Restrict who can create or modify those workloads. Do not rely on a namespace name as the security boundary.

Examples

These excerpts show volume declarations. Selectors, Pod labels, and volumeMounts are omitted. Supply the required fields and supported images for actual use.

Before

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: nginx-deployment
  namespace: default
spec:
  template:
    spec:
      containers:
        - name: nginx
          image: nginx:1.14.2
      volumes:
        - name: static-page-dir
          hostPath:
            path: /var/local/static
            type: DirectoryOrCreate

This configuration provides the host directory /var/local/static to an ordinary application. Mounting the volume makes the application dependent on files on the node.

After

yaml
apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: fluentd-elasticsearch
  namespace: kube-system
spec:
  template:
    spec:
      containers:
        - name: fluentd-elasticsearch
          image: quay.io/fluentd_elasticsearch/fluentd:v2.5.2
      volumes:
        - name: varlog
          hostPath:
            path: /var/log

Access to /var/log can be legitimate for a system log collector. Placement in kube-system does not provide protection by itself; make the actual volumeMounts read-only and review access to the logs.

References