Description
Connecting host logs, configuration or system directories to a container through hostPath can expose node information and files. Actual access depends on the mount wiring, file permissions and other security settings.
Distinguish operational collectors from ordinary applications. Even where access is needed, do not expose the entire host or broad parent directories.
Potential impact
- Sensitive information in host logs or configuration may be exposed.
- Where writes are allowed, file tampering can affect the node and other workloads.
Remediation
- Remove unnecessary sensitive
host_pathmounts. Supply configuration through ConfigMaps or Secrets and application data through suitable CSI or managed storage. - A PVC backed by hostPath retains the same risk, so check the actual storage source.
- Limit essential mounts to minimal paths and read-only access. Read-only mounts can still disclose information; restrict access identities and permission to modify workloads too.
Examples
These partial examples compare host-volume declarations. The first omits the volume name and container mount wiring. Deployment requires complete configuration and a supported image.
Before
resource "kubernetes_pod" "app_pod" {
metadata {
name = "terraform-example"
}
spec {
container {
name = "app-container"
image = "nginx:1.7.9"
}
volume {
host_path {
path = "/var/log"
}
}
}
}
The node’s /var/log is declared as a volume source. This declaration alone does not connect a mount to the container.
After
resource "kubernetes_pod" "app_pod" {
metadata {
name = "terraform-example"
}
spec {
container {
name = "app-container"
image = "nginx:1.7.9"
}
}
}
The hostPath declaration is removed. Check that other volumes or permissions do not provide access to sensitive host files.