Description
An Unmasked proc mount removes the default masking and read-only protections on the container’s /proc. This can expose additional sensitive kernel information or interfaces. It does not automatically reveal every host process: the PID namespace and other permissions also matter.
PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Use Pod Security Admission or a policy engine to require default proc mounts on current clusters.
Potential impact
- Paths in
/procthat are normally masked or protected as read-only can become accessible. - Abuse of accessible kernel interfaces may weaken isolation and workload stability.
Remediation
- Remove
Unmaskedfromallowed_proc_mount_typesin legacy policies and useDefault. - Retain the default proc mount in current workloads, isolating any necessary exception separately.
- Review privileged mode, hostPID and other host-access permissions too.
Examples
These are partial legacy PodSecurityPolicy examples. They compare policy permissions in historical clusters and providers that support this API.
Before
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
allowed_proc_mount_types = ["Unmasked"]
}
}
The policy permits Unmasked. Permission alone does not mean that every Pod actually runs with this mount type.
After
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
allowed_proc_mount_types = ["Default"]
}
}
Only Default is permitted, retaining the usual /proc protections.