# Cis K8S V200 5.2.11

> Minimize the admission of HostPath volumes (Manual)

- Skill: `cyberstrikeus/cis-k8s-v200-5-2-11` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-k8s-v200-5-2-11`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-k8s-v200-5-2-11/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-k8s-v200-5-2-11

---


# 5.2.11 Minimize the admission of HostPath volumes (Manual)

## Profile Applicability

- Level 1 - Master Node

## Description

Do not generally admit containers which make use of `hostPath` volumes.

## Rationale

A container which mounts a `hostPath` volume as part of its specification will have access to the filesystem of the underlying cluster node. The use of `hostPath` volumes may allow containers access to privileged areas of the node filesystem.

There should be at least one admission control policy defined which does not permit containers to mount `hostPath` volumes.

If you need to run containers which require `hostPath` volumes, this should be defined in a separate policy and you should carefully check to ensure that only limited service accounts and users are given permission to use that policy.

## Impact

Pods defined which make use of `hostPath` volumes will not be permitted unless they are run under a specific policy.

## Audit

List the policies in use for each namespace in the cluster, ensure that each policy disallows the admission of containers with `hostPath` volumes.

## Remediation

Add policies to each namespace in the cluster which has user workloads to restrict the admission of containers which use `hostPath` volumes.

## Default Value

By default, there are no restrictions on the creation of `hostPath` volumes.

## References

1. https://kubernetes.io/docs/concepts/security/pod-security-standards/

