Pod shares the host network namespace

Use a separate network namespace for pods that do not need host networking.

Description

host_network = true makes a pod share the node’s network namespace and IP/port space. This reduces separation from host networking and can cause port conflicts or unintended service exposure. External reachability still depends on routing and firewalls, and NetworkPolicy handling of hostNetwork pods depends on the network plugin.

Potential impact

  • Services bound to node interfaces can be exposed more broadly than intended.
  • Port conflicts or access to host networking can affect other services.

Remediation

  • Use host_network = false for ordinary workloads and configure required exposure explicitly through Services or Ingress.
  • Limit exceptions for system workloads that need host networking. Verify actual bind addresses and ports, firewalls, authentication and applicable network policies.

Examples

These existing Pod examples compare network namespace sharing only. Review the image and service exposure paths separately for the deployment.

Before

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    host_network = true

    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

After

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    host_network = false

    container {
      image = "nginx:1.7.9"
      name  = "example"
    }
  }
}

Explanation:

  • Before: The host network namespace is shared.
  • After: Host network sharing is disabled. This setting alone does not remove every external exposure path.

References