Description
host_network = true makes a pod share the node’s network namespace and IP/port space. This reduces separation from host networking and can cause port conflicts or unintended service exposure. External reachability still depends on routing and firewalls, and NetworkPolicy handling of hostNetwork pods depends on the network plugin.
Potential impact
- Services bound to node interfaces can be exposed more broadly than intended.
- Port conflicts or access to host networking can affect other services.
Remediation
- Use
host_network = falsefor ordinary workloads and configure required exposure explicitly through Services or Ingress. - Limit exceptions for system workloads that need host networking. Verify actual bind addresses and ports, firewalls, authentication and applicable network policies.
Examples
These existing Pod examples compare network namespace sharing only. Review the image and service exposure paths separately for the deployment.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
host_network = true
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
host_network = false
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
Explanation:
- Before: The host network namespace is shared.
- After: Host network sharing is disabled. This setting alone does not remove every external exposure path.