GKE Pod Created with a Sensitive hostPath Volume
Description
Detects GKE pod create, update, or patch events that mount sensitive hostPath volumes such as the root filesystem, kubelet paths, or container runtime sockets. This can enable container escape and credential theft. System identities and controller-owned workloads are excluded.
Query · kuery
data_stream.dataset:gcp.audit and event.outcome:success and
event.action:("io.k8s.core.v1.pods.create" or "io.k8s.core.v1.pods.update" or "io.k8s.core.v1.pods.patch") and
gcp.audit.request.spec.volumes.hostPath.path:(
"/" or "/proc" or "/root" or "/var" or "/var/run" or "/var/run/docker.sock" or "/var/run/crio/crio.sock" or
"/var/run/cri-dockerd.sock" or "/var/lib/kubelet" or "/var/lib/kubelet/pki" or "/var/lib/docker/overlay2" or "/etc" or
"/etc/kubernetes" or "/etc/kubernetes/manifests" or "/etc/kubernetes/pki" or "/home/admin"
) and not user.email:system\:* and
not gcp.audit.request.metadata.ownerReferences.kind:("ReplicaSet" or "DaemonSet" or "StatefulSet")
Known false positives
- Node agents and observability DaemonSets commonly mount host paths like /proc or /var/log. Controller ownerReferences exclusions reduce noise; add image exceptions if needed.
Analyst notes
Investigating GKE Pod Created with a Sensitive hostPath Volume
Review gcp.audit.request.spec.volumes.hostPath.path and whether the mount is required for the workload.
Investigation steps
- Confirm the hostPath and container images in the audit request.
- Review
user.email, namespace, and follow-on secret or exec activity.
False positives
- Platform DaemonSets mounting /proc or kubelet paths; validate against known agents.
Setup
The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.