Description
With hostIPC: true, the Pod shares the host’s IPC namespace. This weakens separation from resources such as shared memory and semaphores.
Ordinary applications generally do not need host IPC sharing. Keep the default separation unless the workload has a specific requirement.
Potential impact
- The Pod may have broader access to host IPC resources.
- Isolation between the container and host may be reduced.
- A compromise may increase the risk of exposing host information.
Remediation
- Keep
hostIPC: falsein Pod settings. - Allow exceptions only for system workloads that require host IPC.
- Review hostIPC, hostNetwork and hostPID together, and enforce standards with Pod Security Admission or a policy engine.
Examples
These are namespace-setting excerpts. Manage application execution settings and IPC resource permissions separately.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
hostIPC: true
containers:
- name: sec-ctx-demo
image: busybox
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
hostIPC: false
containers:
- name: sec-ctx-demo
image: busybox
Explanation:
- Before: Sharing host IPC weakens separation between the Pod and host.
- After: Disabling hostIPC preserves the default IPC separation. It does not automatically restrict other host-sharing settings.