Shared host network namespace

Remove unnecessary hostNetwork sharing and manage service network exposure.

Description

With hostNetwork: true, the Pod directly uses the host network namespace. Containers operate on the node’s network, which can cause port conflicts or broader exposure.

Ordinary applications are generally safer using separate Pod networking. Avoid sharing the host network unless a system workload specifically requires it.

Potential impact

  • Direct use of host networking can increase the Pod’s exposure.
  • Port conflicts or unexpected network behavior may occur.
  • A compromise can increase the risk of abusing node network resources.

Remediation

  • Keep hostNetwork: false in Pod settings.
  • Allow host networking only for workloads that require it.
  • Consider a Service or Ingress for external exposure and apply the required authentication and access controls separately.

Examples

These are network-namespace excerpts. Ordinary Pod networking does not by itself block all access from other Pods.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  hostNetwork: true
  containers:
    - name: sec-ctx-demo
      image: busybox

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  containers:
    - name: sec-ctx-demo
      image: busybox

Explanation:

  • Before: Host networking weakens separation between the Pod and node network.
  • After: Omitting hostNetwork preserves the default network namespace separation. Manage Service exposure and network policies separately.

References