Joint Security Assessment Document
Finding: Dragonfly needs HostIPC, HostPID, HostNetwork access
Containers should be isolated from the host machine as much as possible. The hostPID and hostIPC fields in deployment yaml may allow cross-container influence and may expose the host itself to potentially malicious or destructive actions. This control identifies all pods using hostPID or hostIPC privileges.