PodSecurityPolicy permits sharing the host network namespace

A policy permitting host networking can weaken network isolation between Pods and the node.

Description

The legacy PodSecurityPolicy setting hostNetwork: true permits Pods to use the node’s network namespace. Pods that use it share the node’s network interfaces and port space, creating different access paths and a risk of port conflicts. NetworkPolicy behavior also depends on the network plugin.

PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to restrict unnecessary host networking on current clusters.

Potential impact

  • Node network paths may allow access to services that the workload was not intended to reach.
  • Application listeners can conflict with other node services or broaden exposure.
  • Network controls applied to ordinary Pods may not behave the same way.

Remediation

  • Restrict hostNetwork to false in legacy policies and use the separate Pod network for ordinary workloads.
  • Review hostPorts, hostIPC, hostPID, and privileges together.
  • Limit essential system exceptions and verify actual firewall rules, NetworkPolicy behavior, and service connectivity.

Examples

These excerpts show the relevant PSP fields for Kubernetes before 1.25. Other required policy fields are omitted.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: privileged
spec:
  hostNetwork: true

Pods authorized to use the policy can request host networking. Policy permission does not mean that every Pod uses the host network.

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: privileged
spec:
  hostNetwork: false

This policy does not permit host networking. Configure access controls for the ordinary Pod network separately.

References