Skip to content

fix: disable host network and PID namespace sharing in deployment#117

Open
hacktron-app-stg[bot] wants to merge 1 commit into
add-k8s-deploymentfrom
hacktron/fix-42e72c42
Open

fix: disable host network and PID namespace sharing in deployment#117
hacktron-app-stg[bot] wants to merge 1 commit into
add-k8s-deploymentfrom
hacktron/fix-42e72c42

Conversation

@hacktron-app-stg

Copy link
Copy Markdown

Vulnerability

deployment.yaml set hostNetwork: true and hostPID: true on the pod spec (lines 16-17). This merges the container's network and process namespaces with the host node's, allowing the container to:

  • View and potentially manipulate all processes on the host node (hostPID: true).
  • Observe host network interfaces and intercept/sniff host network traffic (hostNetwork: true).

This is a high-severity container-isolation weakness.

Fix

Changed both flags to false, restoring standard namespace isolation between the pod and the host node:

    spec:
      hostNetwork: false
      hostPID: false

These values match the Kubernetes defaults, so the container now runs in its own network and PID namespaces.

Verification

Reviewed the manifest before and after the change; the pod spec no longer opts into host namespaces. Change is minimal and scoped strictly to the reported finding. The repository contains no test infrastructure for Kubernetes manifests, so no automated regression test was added.


Automated fix by Hacktron for finding: https://staging.hacktron.ai/testestesttest/findings/42e72c42-3d3f-4299-892b-800455c319cc

Set hostNetwork and hostPID to false in deployment.yaml to prevent the
container from sharing the host node's network and process namespaces,
which allowed host traffic interception and host process visibility.
@hacktron-app-stg
hacktron-app-stg Bot requested a review from maekuss July 23, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants