Description
The legacy PodSecurityPolicy setting hostNetwork: true permits Pods to use the node’s network namespace. Pods that use it share the node’s network interfaces and port space, creating different access paths and a risk of port conflicts. NetworkPolicy behavior also depends on the network plugin.
PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to restrict unnecessary host networking on current clusters.
Potential impact
- Node network paths may allow access to services that the workload was not intended to reach.
- Application listeners can conflict with other node services or broaden exposure.
- Network controls applied to ordinary Pods may not behave the same way.
Remediation
- Restrict
hostNetworktofalsein legacy policies and use the separate Pod network for ordinary workloads. - Review
hostPorts,hostIPC,hostPID, and privileges together. - Limit essential system exceptions and verify actual firewall rules, NetworkPolicy behavior, and service connectivity.
Examples
These excerpts show the relevant PSP fields for Kubernetes before 1.25. Other required policy fields are omitted.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: privileged
spec:
hostNetwork: true
Pods authorized to use the policy can request host networking. Policy permission does not mean that every Pod uses the host network.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: privileged
spec:
hostNetwork: false
This policy does not permit host networking. Configure access controls for the ordinary Pod network separately.