PSP allows host PID sharing

A PodSecurityPolicy that permits hostPID sharing can allow Pods to share the host process namespace.

Description

Allowing hostPID: true lets Pods share the host process namespace. Containers may then observe host processes or have more opportunities to affect them.

Ordinary applications do not need host PID sharing. Deny it by default in environments that still use PodSecurityPolicy.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. This article concerns legacy clusters or retained PSP resources. On current clusters, use Pod Security Admission or a policy engine such as Gatekeeper or Kyverno to enforce equivalent restrictions.

Potential impact

  • Pods can see more host process information.
  • Isolation between the host and containers may be reduced.
  • Compromised workloads may gain more opportunities for host reconnaissance and further attacks.

Remediation

  • Set hostPID: false in the PSP.
  • Allow exceptions only for system workloads that require host PID access.
  • Review host namespace sharing across hostPID, hostIPC and hostNetwork together.

Examples

These legacy PSP excerpts contain only selected fields. Supply other required fields and authorization to use the policies separately.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: example
spec:
  hostPID: true
  seLinux:
    rule: RunAsAny

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: example
spec:
  hostPID: false
  seLinux:
    rule: RunAsAny

Explanation:

  • Before: Allows Pods that request host PID sharing. It does not require all Pods to share that namespace.
  • After: Prohibits host PID sharing to preserve process-namespace isolation.

References