Description
Allowing Unmasked in the legacy PodSecurityPolicy field allowedProcMountTypes lets containers request removal of default masking and read-only protections for paths such as /proc. This can expose sensitive kernel information or broaden access to protected paths. Use Default for ordinary workloads.
This setting alone does not grant access to every host process or file; the actual scope depends on namespaces, permissions, and the runtime. PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use Pod Security Admission or a replacement policy to enforce default path protections on current clusters.
Potential impact
- System information hidden by default may become visible to the container.
- Combined with additional permissions, broader kernel-interface access can increase the risk of misuse or disruption.
Remediation
- Remove
Unmaskedfrom legacyallowedProcMountTypespolicies and allow onlyDefault. - Keep workload
procMountat its default and remove unnecessary privileges and host namespace sharing. - Verify that required application features still work after migrating the policy.
Examples
These are policy excerpts for clusters that supported PSP. Other required policy fields are omitted, and these resources cannot be applied to Kubernetes 1.25 or later.
Before
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
spec:
allowedProcMountTypes:
- Unmasked
The policy permits containers to request Unmasked. Permission in a policy does not by itself mean that a container uses the option.
After
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
spec:
allowedProcMountTypes:
- Default
Allowing only Default retains default masking and read-only path protections. Restrict other permissions and isolation settings as well.