Description
A PodSecurityPolicy that permits hostPath access with broad paths and write permissions can let workloads read or change node files. Actual access also depends on Pod mounts and file permissions. Check whether volumes allows hostPath itself, as well as the allowedHostPaths restrictions.
PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Apply the required restrictions through supported admission controls on current clusters.
Potential impact
- Even read access can expose sensitive host files.
- Write access can allow changes to node configuration or files used by other workloads.
Remediation
- Prohibit unnecessary hostPath access and use storage suited to the workload.
- Where a legacy PSP needs an exception, allow only approved paths and require
readOnly: truewhen writes are unnecessary. - Review actual mounts, file permissions and other policies the workload can use.
Examples
These excerpts compare path restrictions in a legacy PSP. The complete policy and actual workload mounts are required separately; review the example paths for your environment.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
allowedHostPaths:
- pathPrefix: /dev
readOnly: false
The policy does not require read-only mounts for /dev. Check which host files an allowed workload can actually access.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: example
spec:
allowedHostPaths:
- pathPrefix: /foo
readOnly: true
The permitted path changes to /foo and read-only access is required. Also confirm that exposing its data is appropriate and that the workload needs this path.