> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Minimize The Admission Containers Wishing Share The Host Ipc Namespace

### More Info:

Do not generally permit containers to be run with the hostIPC flag set to true.

### Risk Level

Critical

### Address

Security

### Compliance Standards

* APRA CPS 234 (Australia)
* BSI C5 (Germany)
* Brazil LGPD
* CCPA / CPRA (California)
* CIS Critical Security Controls v8
* CIS GKE
* CMMC 2.0
* CSA Cloud Controls Matrix v4
* DPDPA
* Digital Operational Resilience Act (EU)
* Essential 8
* ISO/IEC 27017
* ISO/IEC 27018
* ISO/IEC 27701
* KSA PDPL
* MAS Technology Risk Management (Singapore)
* MITRE ATT\&CK (Cloud)
* NIS2 Directive
* NIST SP 800-171
* NYDFS 23 NYCRR 500
* SWIFT Customer Security Controls Framework
* Sarbanes-Oxley IT General Controls
* UK NCSC Cyber Assessment Framework

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. **Identify all pods using `hostIPC: true`**
           * Run on: any machine with `kubectl` access
           ```sh theme={null}
           kubectl get pods --all-namespaces -o json | jq -r '
             .items[]
             | select(.spec.hostIPC == true)
             | "\(.metadata.namespace) \(.metadata.name)"'
           ```
           If `jq` is unavailable:
           ```sh theme={null}
           kubectl get pods --all-namespaces -o jsonpath='{range .items[?(@.spec.hostIPC==true)]}{.metadata.namespace}{" "}{.metadata.name}{"\n"}{end}'
           ```

        2. **Map pods to their controllers and manifests**
           * For each `<namespace> <pod>` from step 1, run:
           ```sh theme={null}
           kubectl -n <namespace> get pod <pod> -o json | jq -r '
             .metadata.ownerReferences[]? 
             | "\(.kind) \(.name)"'
           ```
           * Note the owning `Deployment` / `StatefulSet` / `DaemonSet` / `Job` / `ReplicaSet` (or `Pod` if standalone). Locate and open the corresponding manifest in your Git/IaC repo if applicable.

        3. **Review necessity of `hostIPC` per workload**
           * For each owning object, inspect the spec:
           ```sh theme={null}
           kubectl -n <namespace> get <kind> <name> -o yaml | sed -n "/spec:/,/status:/p" | sed '/status:/q'
           ```
           * Look for `hostIPC: true`. With application owners, confirm whether sharing the host IPC namespace is strictly required (e.g., for specific low-level IPC use cases). If not clearly justified, mark it for removal.

        4. **Adjust manifests to remove or avoid `hostIPC: true`**
           * In your deployment manifests (Git/IaC or exported YAML), remove the `hostIPC: true` line from the pod spec, or set it to `false` only if you must be explicit:
           ```yaml theme={null}
           spec:
             # remove this if present
             # hostIPC: true
           ```
           * Apply the corrected manifests:
           ```sh theme={null}
           kubectl apply -f <corrected-manifest>.yaml
           ```

        5. **Optionally define restrictive policy (PSP-equivalent or admission policy)**
           * If you use PodSecurityPolicy (legacy) or a replacement (e.g., Pod Security Admission, Gatekeeper, Kyverno), author a policy that disallows `hostIPC: true` except in tightly scoped namespaces. Example evidence command to inspect existing PSPs (if in use):
           ```sh theme={null}
           kubectl get psp -o yaml | grep -nA5 hostIPC
           ```
           * For Pod Security Admission, verify namespaces are at least `baseline` (which disallows host namespaces by default):
           ```sh theme={null}
           kubectl get ns -o jsonpath='{range .items[*]}{.metadata.name}{" "}{.metadata.labels}{"\n"}{end}'
           ```

        6. **Verify no remaining pods use `hostIPC: true`**
           * After changes roll out, rerun:
           ```sh theme={null}
           kubectl get pods --all-namespaces -o jsonpath='{range .items[?(@.spec.hostIPC==true)]}{.metadata.namespace}{" "}{.metadata.name}{"\n"}{end}'
           ```
           * Confirm the command returns no output, or only the small, explicitly approved set you intended to keep. Document any approved exceptions with their justification.
      </Accordion>

      <Accordion title="Using kubectl">
        ```bash theme={null}
        # 1) List all pods that request hostIPC
        # Run on: any machine with kubectl access
        kubectl get pods -A \
          -o custom-columns='NAMESPACE:.metadata.namespace,NAME:.metadata.name,HOST_IPC:.spec.hostIPC' \
          --no-headers | grep -w true || echo "No pods with hostIPC: true found"
        ```

        **Interpretation:**\
        Any line printed (not the final “No pods…” message) shows a pod with `HOST_IPC` set to `true`. Each such pod needs review: confirm whether sharing the host IPC namespace is strictly required.

        ***

        ```bash theme={null}
        # 2) Show full specs for pods using hostIPC, for detailed review
        # Run on: any machine with kubectl access
        for ns in $(kubectl get pods -A \
          -o custom-columns='NAMESPACE:.metadata.namespace,HOST_IPC:.spec.hostIPC' \
          --no-headers | awk '$2=="true"{print $1}' | sort -u); do
          echo "### Namespace: $ns"
          kubectl get pods -n "$ns" \
            -o yaml | awk '/hostIPC: true/{p=1} p'
        done
        ```

        **Interpretation:**\
        Inspect each pod spec that includes `hostIPC: true`. Use this to decide which workloads can safely be modified to drop `hostIPC`.

        ***

        ```bash theme={null}
        # 3) List namespaces that currently allow hostIPC via security policies (if using PodSecurityPolicy)
        # Run on: any machine with kubectl access

        # Show all PSPs and whether they allow hostIPC
        kubectl get podsecuritypolicies.policy \
          -o custom-columns='NAME:.metadata.name,HOST_IPC:.spec.hostIPC' \
          --no-headers 2>/dev/null || echo "No PodSecurityPolicies found (or PSP not enabled)"

        # Show which service accounts are bound to any PSP that allows hostIPC
        for psp in $(kubectl get podsecuritypolicies.policy \
          -o jsonpath='{range .items[?(@.spec.hostIPC==true)]}{.metadata.name}{"\n"}{end}' 2>/dev/null); do
          echo "### PSP allowing hostIPC: $psp"
          kubectl get clusterrolebindings,rolebindings -A \
            -o jsonpath="{range .items[?(@.roleRef.kind=='PodSecurityPolicy' && @.roleRef.name=='$psp')]}{.kind}{'\t'}{.metadata.namespace}{'\t'}{.metadata.name}{'\n'}{end}" 2>/dev/null
        done
        ```

        **Interpretation:**\
        Any PodSecurityPolicy with `.spec.hostIPC: true` permits use of the host IPC namespace. Any role/clusterrolebinding referencing such a PSP extends that permission to the bound subjects (service accounts, users, groups). Those namespaces and identities need review to confirm hostIPC use is intentional and tightly scoped.

        ***

        ```bash theme={null}
        # 4) If using Pod Security Admission (built-in Pod Security Standards), check namespace levels
        # Run on: any machine with kubectl access
        kubectl get ns -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.metadata.labels}{"\n"}{end}'
        ```

        **Interpretation:**\
        Identify namespaces not labeled with a restrictive policy (e.g., `pod-security.kubernetes.io/enforce=restricted`). Namespaces with no or permissive labels are more likely to admit pods with `hostIPC: true` and should be reviewed and, where appropriate, tightened.

        ***

        ```bash theme={null}
        # 5) Verify after review/changes: re-scan for hostIPC pods
        # Run on: any machine with kubectl access
        kubectl get pods -A \
          -o custom-columns='NAMESPACE:.metadata.namespace,NAME:.metadata.name,HOST_IPC:.spec.hostIPC' \
          --no-headers | grep -w true || echo "No pods with hostIPC: true found"
        ```

        **Interpretation:**\
        If only the final “No pods with hostIPC: true found” line appears, there are currently no pods requesting the host IPC namespace. If any pods still show `HOST_IPC` as `true`, those remaining cases must be explicitly accepted as exceptions or further remediated.
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        # Report pods, workloads, and namespaces that allow hostIPC:true
        # Run on any machine with kubectl access and current-context set to the target cluster

        set -euo pipefail

        echo "=== 1) All pods currently running with hostIPC: true (cluster-wide) ==="
        kubectl get pods -A -o json \
          | jq -r '
            .items[]
            | select(.spec.hostIPC == true)
            | [.metadata.namespace, .metadata.name, .spec.serviceAccountName]
            | @tsv' \
          | awk 'BEGIN {print "NAMESPACE\tPOD\tSERVICEACCOUNT"}1'

        echo
        echo "=== 2) Namespaces that currently contain any pod with hostIPC: true ==="
        kubectl get pods -A -o json \
          | jq -r '
            .items[]
            | select(.spec.hostIPC == true)
            | .metadata.namespace' \
          | sort -u

        echo
        echo "=== 3) Workloads (Deployments/DaemonSets/StatefulSets/Jobs/CronJobs) configured with hostIPC: true ==="

        for kind in deployment daemonset statefulset job cronjob; do
          echo
          echo "--- $kind objects with hostIPC: true ---"
          kubectl get "$kind" -A -o json 2>/dev/null \
            | jq -r '
                .items[]
                | select(.spec.template.spec.hostIPC == true)
                | [.kind, .metadata.namespace, .metadata.name]
                | @tsv' \
            | awk 'BEGIN {print "KIND\tNAMESPACE\tNAME"}1' || true
        done

        echo
        echo "=== 4) PodSecurityPolicy objects that allow hostIPC ==="
        # PSP is deprecated but still used in some clusters; include for completeness
        if kubectl api-resources 2>/dev/null | grep -q "^podsecuritypolicies.extensions"; then
          kubectl get podsecuritypolicies -o json \
            | jq -r '
                .items[]
                | select(.spec.hostIPC == true)
                | .metadata.name' \
            | awk 'BEGIN {print "PSP_NAME"}1'
        else
          echo "PodSecurityPolicy API not found in this cluster."
        fi

        echo
        echo "=== 5) Namespaces and their Pod Security admission labels (if any) ==="
        kubectl get ns --show-labels \
          | awk '
              NR==1 {print; next}
              {
                ns=$1; labels=$NF;
                printf "%-30s %s\n", ns, labels
              }'
        ```

        **How to interpret the output**

        * **Problems / items to review:**
          * Any entry in section **1)**: pods listed there are currently running with `hostIPC: true`.
          * Any namespace listed in section **2)**: these namespaces host at least one such pod.
          * Any workload listed in section **3)**: these controllers are configured to create pods with `hostIPC: true` (persistent risk).
          * Any PSP listed in section **4)** with `hostIPC` allowed: these policies permit `hostIPC: true`.
        * These outputs should be reviewed to decide whether `hostIPC: true` is strictly necessary and, if not, have manifests/PSPs updated so that `.spec.hostIPC` is omitted or set to `false`.
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>

### Additional Reading:

* [https://kubernetes.io/docs/concepts/security/pod-security-standards/](https://kubernetes.io/docs/concepts/security/pod-security-standards/)
