Kubernetes v1.37 adds permission modes for emptyDir (a temporary writable volume) and bind mount options.
Bind mount options—flags for mounting a volume in a container—let users set noexec, nosuid, and nodev. The noexec flag blocks direct execution of binaries on the mounted filesystem.
Both capabilities are Alpha features and require enabling VolumeBindMountOptions and EmptyDirVolumeMode on the API server and kubelet. If these settings are omitted, the previous default behavior remains, including 0777 permissions.
Claim check:
- Kubernetes v1.37 adds permission modes for emptyDir and bind mount options. (confirmed by the publication itself: evidence; «Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options.»)
- Bind mount options let users set noexec, nosuid, and nodev. (confirmed by the publication itself: evidence; «Supporting noexec , nodev , and nosuid gives users a native way to harden volume mounts to match security benchmarks and policy.»)
- The noexec flag blocks direct execution of binaries on the mounted filesystem. (confirmed by the publication itself: evidence; «noexec : Do not permit direct execution of any binaries on the mounted filesystem.»)
- Both capabilities are Alpha features and require enabling VolumeBindMountOptions and EmptyDirVolumeMode on the API server and kubelet. (confirmed by the publication itself: evidence; «Both features are behind Alpha feature gates in Kubernetes v1.37. To use them, enable VolumeBindMountOptions and EmptyDirVolumeMode on the API server and kubelet.»)
- If these settings are omitted, the previous default behavior remains, including 0777 permissions. (confirmed by the publication itself: evidence; «If you omit bindMountOptions or do not set an emptyDir mode , you get standard default behaviors (like 0777 permissions) exactly as before.»)
Primary sources:
score 72.7 out of 100 · kind: release