Description
Mounting sensitive host directories such as /proc, /etc, /var, /root, or / through hostPath can expose node configuration, process information, and system files to containers. Some system agents need this access, but ordinary applications should avoid unnecessary access to the host.
The actual impact depends on the mounted path and file permissions. A read-only mount limits writes but does not prevent information disclosure.
Potential impact
- Sensitive node configuration, logs, or credentials may be exposed.
- Write access can allow host-file tampering or service disruption.
- A compromised container may have a greater impact on the node or other workloads.
Remediation
- Remove unnecessary sensitive-directory mounts. Consider ConfigMaps for configuration, Secrets for sensitive values, and PVCs backed by suitable storage for persistent data.
- Limit essential exceptions to approved workloads and the smallest necessary paths; mount them read-only when writes are not required.
- When changing storage, migrate needed data and permissions and verify that the application actually uses the new path.
Examples
These examples show storage configurations for different workloads. The second is not a direct migration of the first application.
Before
apiVersion: v1
kind: Pod
metadata:
name: web-server-pod
spec:
volumes:
- name: nginx-host-config
hostPath:
path: /etc/nginx
containers:
- name: nginx-container
image: nginx
volumeMounts:
- mountPath: /etc/nginx
name: nginx-host-config
The container mounts the node’s /etc/nginx directly. Where file permissions allow it, the container can read or change host configuration.
After
apiVersion: v1
kind: Pod
metadata:
name: redis-empty-dir
spec:
containers:
- name: redis
image: redis
volumeMounts:
- name: redis-storage
mountPath: /data/redis
volumes:
- name: redis-storage
emptyDir: {}
emptyDir does not directly expose the specified sensitive host directory. Its data is deleted when the Pod is removed from the node, so it is not a replacement for persistent storage. Configure the application separately to store data in /data/redis.