Description
In a legacy PodSecurityPolicy, hostIPC: true permits Pods to share the host IPC namespace. A Pod that uses this option gains visibility into a broader set of IPC resources, such as shared memory, semaphores, and message queues on the node. Reading or changing their data remains subject to the resources’ permissions.
PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to restrict host IPC sharing on current clusters.
Potential impact
- IPC resources and their state may become visible to workloads.
- With sufficient permissions, access can affect other processes’ data or operation.
Remediation
- Set
hostIPCtofalsein legacy policies and remove unnecessary host IPC sharing from actual Pods. - Restrict
hostPID,hostNetwork, and privileged execution as well. - Approve only essential system-tool exceptions and verify required features under the enforced policy.
Examples
These excerpts show IPC controls in PSP for Kubernetes before 1.25. Other required policy fields are omitted.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
hostIPC: true
Pods authorized to use this policy can request host IPC sharing. The setting does not force every Pod to share it.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
hostIPC: false
This policy does not permit host IPC sharing. Check that other available policies or exceptions do not grant broader access.