Description
A Pod with hostPID: true shares the host process ID namespace. Containers can see processes belonging to the node and other workloads, exposing information that ordinary applications do not need.
Visibility is different from control: sending signals or tracing processes remains subject to additional checks such as user IDs and Linux capabilities.
Potential impact
- Operational information, including running processes and command arguments, may be exposed.
- With additional permissions, this access can help disrupt other processes or obtain sensitive information.
Remediation
- Remove unnecessary
hostPIDsettings or set them tofalse. - Review
hostIPC,hostNetwork,privileged, and additional capabilities as well. - Limit exceptions for diagnostic or operational tools to approved workloads and control who may use them.
Examples
These examples compare whether a Pod shares the host PID namespace. Configure the image and command for the intended workload.
Before
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
hostPID: true
containers:
- name: sec-ctx-demo
image: busybox
Sharing the host PID namespace increases visibility into node processes.
After
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
spec:
hostPID: false
containers:
- name: sec-ctx-demo
image: busybox
The Pod does not share the host PID namespace. Maintain separate controls on file access and other namespace sharing.