Description
Permitting host IPC lets Pods use the same IPC namespace as the node. Workloads that actually share it may access shared memory or message queues according to object permissions, weakening isolation of interprocess communication.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Enforce restrictions with Pod Security Admission or a policy engine on current clusters.
Potential impact
- IPC data may be exposed or modified where object permissions allow access.
- Interference with shared IPC resources may affect other processes on the node.
Remediation
- Set
spec.host_ipc = falsein legacy PSPs. - Separate workloads requiring host IPC with dedicated policies and nodes, and restrict actual object permissions.
- Review hostNetwork, hostPID and privileged mode too.
Examples
These partial examples target historical environments supporting PSP. They compare the IPC permission and omit other required policy settings.
Before
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
host_ipc = true
}
}
Pods authorized to use the policy can request host IPC. It does not automatically enable sharing for every Pod.
After
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
host_ipc = false
}
}
The policy prohibits host IPC sharing. Also check the actual workloads and other applicable policies.