Description
A pod with host_pid = true shares the host PID namespace. Seeing host processes reduces isolation and, combined with other permissions or vulnerabilities, can allow interference with them. Process visibility alone does not grant permission to signal or debug every process.
Potential impact
- Host process information can be exposed and used for reconnaissance.
- Additional permissions or vulnerabilities can enable interference with host processes and service disruption.
Remediation
- Use
host_pid = falsefor ordinary workloads. Limit exceptions for system tools that need to observe host processes after reviewing their purpose and permissions. - Use non-root execution and minimum capabilities, and restrict unnecessary host namespace sharing through Pod Security Admission or a policy engine.
Examples
These existing Pod examples compare host_pid only. Use a maintained image for deployment and separately assess administration tools that need an exception.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
host_pid = true
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
host_pid = false
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
Explanation:
- Before: The host PID namespace is shared.
- After: Host PID namespace sharing is disabled. Review other host access permissions separately.