Kubernetes security policy permits Unmasked proc mounts

Remove permission for Unmasked proc mounts to retain default /proc protections.

Description

An Unmasked proc mount removes the default masking and read-only protections on the container’s /proc. This can expose additional sensitive kernel information or interfaces. It does not automatically reveal every host process: the PID namespace and other permissions also matter.

PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Use Pod Security Admission or a policy engine to require default proc mounts on current clusters.

Potential impact

  • Paths in /proc that are normally masked or protected as read-only can become accessible.
  • Abuse of accessible kernel interfaces may weaken isolation and workload stability.

Remediation

  • Remove Unmasked from allowed_proc_mount_types in legacy policies and use Default.
  • Retain the default proc mount in current workloads, isolating any necessary exception separately.
  • Review privileged mode, hostPID and other host-access permissions too.

Examples

These are partial legacy PodSecurityPolicy examples. They compare policy permissions in historical clusters and providers that support this API.

Before

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    allowed_proc_mount_types = ["Unmasked"]
  }
}

The policy permits Unmasked. Permission alone does not mean that every Pod actually runs with this mount type.

After

hcl
resource "kubernetes_pod_security_policy" "policy" {
  metadata {
    name = "terraform-example"
  }

  spec {
    allowed_proc_mount_types = ["Default"]
  }
}

Only Default is permitted, retaining the usual /proc protections.

References