Description
A pod with host_ipc = true shares the host IPC namespace. This can broaden access to host IPC resources such as shared memory and semaphores, weakening container isolation. Reading or modifying those resources remains subject to their permissions and other access controls.
Potential impact
- Host IPC resources can expose or allow modification of data where permissions permit it.
- Interference with or exhaustion of IPC resources can affect other processes.
Remediation
- Use
host_ipc = falsefor workloads that do not need host IPC sharing. Limit exceptions after reviewing the system tool’s purpose and access permissions. - Use non-root execution and minimum permissions, and restrict unnecessary host_ipc use through Pod Security Admission or a policy engine.
Examples
These existing Pod examples compare host IPC sharing only. Use a maintained image for deployment.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
host_ipc = true
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
host_ipc = false
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
Explanation:
- Before: The host IPC namespace is shared.
- After: Host IPC namespace sharing is disabled.