Shared host IPC namespace

Remove unnecessary hostIPC sharing to preserve separation from host IPC resources.

Description

With hostIPC: true, the Pod shares the host’s IPC namespace. This weakens separation from resources such as shared memory and semaphores.

Ordinary applications generally do not need host IPC sharing. Keep the default separation unless the workload has a specific requirement.

Potential impact

  • The Pod may have broader access to host IPC resources.
  • Isolation between the container and host may be reduced.
  • A compromise may increase the risk of exposing host information.

Remediation

  • Keep hostIPC: false in Pod settings.
  • Allow exceptions only for system workloads that require host IPC.
  • Review hostIPC, hostNetwork and hostPID together, and enforce standards with Pod Security Admission or a policy engine.

Examples

These are namespace-setting excerpts. Manage application execution settings and IPC resource permissions separately.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  hostIPC: true
  containers:
    - name: sec-ctx-demo
      image: busybox

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  hostIPC: false
  containers:
    - name: sec-ctx-demo
      image: busybox

Explanation:

  • Before: Sharing host IPC weakens separation between the Pod and host.
  • After: Disabling hostIPC preserves the default IPC separation. It does not automatically restrict other host-sharing settings.

References