Kubernetes PodSecurityPolicy permits host IPC sharing

Block unnecessary sharing of the host IPC namespace through admission policy.

Description

Permitting host IPC lets Pods use the same IPC namespace as the node. Workloads that actually share it may access shared memory or message queues according to object permissions, weakening isolation of interprocess communication.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Enforce restrictions with Pod Security Admission or a policy engine on current clusters.

Potential impact

  • IPC data may be exposed or modified where object permissions allow access.
  • Interference with shared IPC resources may affect other processes on the node.

Remediation

  • Set spec.host_ipc = false in legacy PSPs.
  • Separate workloads requiring host IPC with dedicated policies and nodes, and restrict actual object permissions.
  • Review hostNetwork, hostPID and privileged mode too.

Examples

These partial examples target historical environments supporting PSP. They compare the IPC permission and omit other required policy settings.

Before

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    host_ipc = true
  }
}

Pods authorized to use the policy can request host IPC. It does not automatically enable sharing for every Pod.

After

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    host_ipc = false
  }
}

The policy prohibits host IPC sharing. Also check the actual workloads and other applicable policies.

References