PodSecurityPolicy allows host network sharing 이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다. Id: kubernetes-psp-containers-share-host-network-namespace
Platform: Kubernetes
Severity: High
Category: Insecure Configurations
Learn More Description PodSecurityPolicy resources must not allow containers to share the host network namespace.
When ‘spec.hostNetwork’ is true, pods gain access to the host network namespace, increasing privilege and network exposure.
The ‘spec.hostNetwork’ field should be set to false or omitted to prevent pods from sharing the host network namespace.
Compliant Code Examples apiVersion : policy/v1beta1
kind : PodSecurityPolicy
metadata :
name : privileged
annotations :
seccomp.security.alpha.kubernetes.io/allowedProfileNames : '*'
spec :
privileged : true
allowPrivilegeEscalation : true
allowedCapabilities :
- '*'
volumes :
- '*'
hostNetwork : false
hostPorts :
- min : 0
max : 65535
hostIPC : true
hostPID : true
runAsUser :
rule : 'RunAsAny'
seLinux :
rule : 'RunAsAny'
supplementalGroups :
rule : 'RunAsAny'
fsGroup :
rule : 'RunAsAny'
Non-Compliant Code Examples apiVersion : policy/v1beta1
kind : PodSecurityPolicy
metadata :
name : privileged
annotations :
seccomp.security.alpha.kubernetes.io/allowedProfileNames : '*'
spec :
privileged : true
allowPrivilegeEscalation : true
allowedCapabilities :
- '*'
volumes :
- '*'
hostNetwork : true
hostPorts :
- min : 0
max : 65535
hostIPC : true
hostPID : true
runAsUser :
rule : 'RunAsAny'
seLinux :
rule : 'RunAsAny'
supplementalGroups :
rule : 'RunAsAny'
fsGroup :
rule : 'RunAsAny'