Kubernetes configuration allows an Unmasked proc mount

Allowing an Unmasked proc mount can remove the container runtime’s default path protections.

Description

Allowing Unmasked in the legacy PodSecurityPolicy field allowedProcMountTypes lets containers request removal of default masking and read-only protections for paths such as /proc. This can expose sensitive kernel information or broaden access to protected paths. Use Default for ordinary workloads.

This setting alone does not grant access to every host process or file; the actual scope depends on namespaces, permissions, and the runtime. PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to enforce default path protections on current clusters.

Potential impact

  • System information hidden by default may become visible to the container.
  • Combined with additional permissions, broader kernel-interface access can increase the risk of misuse or disruption.

Remediation

  • Remove Unmasked from legacy allowedProcMountTypes policies and allow only Default.
  • Keep workload procMount at its default and remove unnecessary privileges and host namespace sharing.
  • Verify that required application features still work after migrating the policy.

Examples

These are policy excerpts for clusters that supported PSP. Other required policy fields are omitted, and these resources cannot be applied to Kubernetes 1.25 or later.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  allowedProcMountTypes:
    - Unmasked

The policy permits containers to request Unmasked. Permission in a policy does not by itself mean that a container uses the option.

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: restricted
spec:
  allowedProcMountTypes:
    - Default

Allowing only Default retains default masking and read-only path protections. Restrict other permissions and isolation settings as well.

References