Kubernetes workload uses sensitive host directories

Restrict mounts of sensitive host directories to protect node information and files.

Description

Connecting host logs, configuration or system directories to a container through hostPath can expose node information and files. Actual access depends on the mount wiring, file permissions and other security settings.

Distinguish operational collectors from ordinary applications. Even where access is needed, do not expose the entire host or broad parent directories.

Potential impact

  • Sensitive information in host logs or configuration may be exposed.
  • Where writes are allowed, file tampering can affect the node and other workloads.

Remediation

  • Remove unnecessary sensitive host_path mounts. Supply configuration through ConfigMaps or Secrets and application data through suitable CSI or managed storage.
  • A PVC backed by hostPath retains the same risk, so check the actual storage source.
  • Limit essential mounts to minimal paths and read-only access. Read-only mounts can still disclose information; restrict access identities and permission to modify workloads too.

Examples

These partial examples compare host-volume declarations. The first omits the volume name and container mount wiring. Deployment requires complete configuration and a supported image.

Before

hcl
resource "kubernetes_pod" "app_pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      name  = "app-container"
      image = "nginx:1.7.9"
    }

    volume {
      host_path {
        path = "/var/log"
      }
    }
  }
}

The node’s /var/log is declared as a volume source. This declaration alone does not connect a mount to the container.

After

hcl
resource "kubernetes_pod" "app_pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      name  = "app-container"
      image = "nginx:1.7.9"
    }
  }
}

The hostPath declaration is removed. Check that other volumes or permissions do not provide access to sensitive host files.

References