Kubernetes workload mounts a sensitive OS directory

Mounting sensitive host directories through hostPath broadens access to node information and files.

Description

Mounting sensitive host directories such as /proc, /etc, /var, /root, or / through hostPath can expose node configuration, process information, and system files to containers. Some system agents need this access, but ordinary applications should avoid unnecessary access to the host.

The actual impact depends on the mounted path and file permissions. A read-only mount limits writes but does not prevent information disclosure.

Potential impact

  • Sensitive node configuration, logs, or credentials may be exposed.
  • Write access can allow host-file tampering or service disruption.
  • A compromised container may have a greater impact on the node or other workloads.

Remediation

  • Remove unnecessary sensitive-directory mounts. Consider ConfigMaps for configuration, Secrets for sensitive values, and PVCs backed by suitable storage for persistent data.
  • Limit essential exceptions to approved workloads and the smallest necessary paths; mount them read-only when writes are not required.
  • When changing storage, migrate needed data and permissions and verify that the application actually uses the new path.

Examples

These examples show storage configurations for different workloads. The second is not a direct migration of the first application.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: web-server-pod
spec:
  volumes:
    - name: nginx-host-config
      hostPath:
        path: /etc/nginx
  containers:
    - name: nginx-container
      image: nginx
      volumeMounts:
        - mountPath: /etc/nginx
          name: nginx-host-config

The container mounts the node’s /etc/nginx directly. Where file permissions allow it, the container can read or change host configuration.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: redis-empty-dir
spec:
  containers:
    - name: redis
      image: redis
      volumeMounts:
        - name: redis-storage
          mountPath: /data/redis
  volumes:
    - name: redis-storage
      emptyDir: {}

emptyDir does not directly expose the specified sensitive host directory. Its data is deleted when the Pod is removed from the node, so it is not a replacement for persistent storage. Configure the application separately to store data in /data/redis.

References