← Policy catalog
</> ValidatingAdmissionPolicy · Apache-2.0

Shares the Host User Namespace

pod-hostusers

severityHigh resourcePods productKubernetes bundles1

Running in the host user namespace removes UID remapping, so container root is real root on the node and any escape or shared host resource is entered with full node privileges.

Rejects unless

!has(object.spec.hostUsers) || object.spec.hostUsers == false

Using hostUsers is disallowed. spec.hostUsers must be undefined or set to false.

Remediation

Set spec.hostUsers to false so the pod runs in its own user namespace with container UIDs remapped away from node root. Field: spec.hostUsers.

Applies to

  • pods · v1 · CREATE, UPDATE

Manifest

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
  name: pod-hostusers
  annotations:
    kubeapt.io/uuid: "1a5efbbe-2a1f-4840-a4fd-19fec7dab8bc"
    security.kubeapt.io/displayName: "Shares the Host User Namespace"
    security.kubeapt.io/description: "Running in the host user namespace removes UID remapping, so container root is real root on the node and any escape or shared host resource is entered with full node privileges."
    security.kubeapt.io/resource: "Pods"
    security.kubeapt.io/severity: "High"
    security.kubeapt.io/remediation: "Set spec.hostUsers to false so the pod runs in its own user namespace with container UIDs remapped away from node root. Field: spec.hostUsers."
    security.kubeapt.io/product: "Kubernetes"
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
    - apiGroups:
      - ''
      apiVersions:
      - v1
      operations:
      - CREATE
      - UPDATE
      resources:
      - pods
  validations:
  - expression: |
      !has(object.spec.hostUsers) || object.spec.hostUsers == false
    message: |
      Using hostUsers is disallowed. spec.hostUsers must be undefined or set to false.

Save it as pod-hostusers.yaml — the commands below assume that name.

Validate with kubeapt

Check a workload against this one policy, before anything is installed on a cluster.

$ kubeapt validate -p ./pod-hostusers.yaml -r ./workload.yaml

Or without the file, from the published policy set — -r takes a directory too:

$ kubeapt policies download && kubeapt validate --policy-name pod-hostusers -r ./manifests

Or against every namespace in the cluster your kubeconfig points at:

$ kubeapt validate --policy-name pod-hostusers -A