Description
With hostNetwork: true, the Pod directly uses the host network namespace. Containers operate on the node’s network, which can cause port conflicts or broader exposure.
Ordinary applications are generally safer using separate Pod networking. Avoid sharing the host network unless a system workload specifically requires it.
Potential impact
- Direct use of host networking can increase the Pod’s exposure.
- Port conflicts or unexpected network behavior may occur.
- A compromise can increase the risk of abusing node network resources.
Remediation
- Keep
hostNetwork: falsein Pod settings. - Allow host networking only for workloads that require it.
- Consider a Service or Ingress for external exposure and apply the required authentication and access controls separately.
Examples
These are network-namespace excerpts. Ordinary Pod networking does not by itself block all access from other Pods.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
hostNetwork: true
containers:
- name: sec-ctx-demo
image: busybox
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
containers:
- name: sec-ctx-demo
image: busybox
Explanation:
- Before: Host networking weakens separation between the Pod and node network.
- After: Omitting hostNetwork preserves the default network namespace separation. Manage Service exposure and network policies separately.