Container shares the host PID namespace

Disable host_pid for pods that do not need access to host processes.

Description

A pod with host_pid = true shares the host PID namespace. Seeing host processes reduces isolation and, combined with other permissions or vulnerabilities, can allow interference with them. Process visibility alone does not grant permission to signal or debug every process.

Potential impact

  • Host process information can be exposed and used for reconnaissance.
  • Additional permissions or vulnerabilities can enable interference with host processes and service disruption.

Remediation

  • Use host_pid = false for ordinary workloads. Limit exceptions for system tools that need to observe host processes after reviewing their purpose and permissions.
  • Use non-root execution and minimum capabilities, and restrict unnecessary host namespace sharing through Pod Security Admission or a policy engine.

Examples

These existing Pod examples compare host_pid only. Use a maintained image for deployment and separately assess administration tools that need an exception.

Before

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    host_pid = true

    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

After

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    host_pid = false

    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

Explanation:

  • Before: The host PID namespace is shared.
  • After: Host PID namespace sharing is disabled. Review other host access permissions separately.

References