HostPath restrictions need review in PodSecurityPolicy

Allow essential hostPath access only through narrow paths and minimal permissions.

Description

A PodSecurityPolicy that permits hostPath access with broad paths and write permissions can let workloads read or change node files. Actual access also depends on Pod mounts and file permissions. Check whether volumes allows hostPath itself, as well as the allowedHostPaths restrictions.

PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Apply the required restrictions through supported admission controls on current clusters.

Potential impact

  • Even read access can expose sensitive host files.
  • Write access can allow changes to node configuration or files used by other workloads.

Remediation

  • Prohibit unnecessary hostPath access and use storage suited to the workload.
  • Where a legacy PSP needs an exception, allow only approved paths and require readOnly: true when writes are unnecessary.
  • Review actual mounts, file permissions and other policies the workload can use.

Examples

These excerpts compare path restrictions in a legacy PSP. The complete policy and actual workload mounts are required separately; review the example paths for your environment.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: example
spec:
  allowedHostPaths:
    - pathPrefix: /dev
      readOnly: false

The policy does not require read-only mounts for /dev. Check which host files an allowed workload can actually access.

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: example
spec:
  allowedHostPaths:
    - pathPrefix: /foo
      readOnly: true

The permitted path changes to /foo and read-only access is required. Also confirm that exposing its data is appropriate and that the workload needs this path.

References