Description
Allowing hostPID: true lets Pods share the host process namespace. Containers may then observe host processes or have more opportunities to affect them.
Ordinary applications do not need host PID sharing. Deny it by default in environments that still use PodSecurityPolicy.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. This article concerns legacy clusters or retained PSP resources. On current clusters, use Pod Security Admission or a policy engine such as Gatekeeper or Kyverno to enforce equivalent restrictions.
Potential impact
- Pods can see more host process information.
- Isolation between the host and containers may be reduced.
- Compromised workloads may gain more opportunities for host reconnaissance and further attacks.
Remediation
- Set
hostPID: falsein the PSP. - Allow exceptions only for system workloads that require host PID access.
- Review host namespace sharing across hostPID, hostIPC and hostNetwork together.
Examples
These legacy PSP excerpts contain only selected fields. Supply other required fields and authorization to use the policies separately.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
hostPID: true
seLinux:
rule: RunAsAny
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
hostPID: false
seLinux:
rule: RunAsAny
Explanation:
- Before: Allows Pods that request host PID sharing. It does not require all Pods to share that namespace.
- After: Prohibits host PID sharing to preserve process-namespace isolation.