Kubernetes workload shares the host PID namespace

Using hostPID shares the node’s process namespace with a container and weakens isolation.

Description

A Pod with hostPID: true shares the host process ID namespace. Containers can see processes belonging to the node and other workloads, exposing information that ordinary applications do not need.

Visibility is different from control: sending signals or tracing processes remains subject to additional checks such as user IDs and Linux capabilities.

Potential impact

  • Operational information, including running processes and command arguments, may be exposed.
  • With additional permissions, this access can help disrupt other processes or obtain sensitive information.

Remediation

  • Remove unnecessary hostPID settings or set them to false.
  • Review hostIPC, hostNetwork, privileged, and additional capabilities as well.
  • Limit exceptions for diagnostic or operational tools to approved workloads and control who may use them.

Examples

These examples compare whether a Pod shares the host PID namespace. Configure the image and command for the intended workload.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  hostPID: true
  containers:
    - name: sec-ctx-demo
      image: busybox

Sharing the host PID namespace increases visibility into node processes.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo
spec:
  hostPID: false
  containers:
    - name: sec-ctx-demo
      image: busybox

The Pod does not share the host PID namespace. Maintain separate controls on file access and other namespace sharing.

References