# Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Kubernetes
- Category: Infrastructure
- Original publication time: 2026-09-16T18:30:00Z
- First observed by NexusTechWire: 2026-10-01T15:54:35Z
- Original source: https://kubernetes.io/blog/2026/09/16/kubernetes-v1-37-hardening-container-storage/
- NexusTechWire record: https://nexustechwire.com/news/news-b402f515f974f7c95e16

## From the publisher

Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentals Before diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flags When Linux mounts or remounts a directory, Virtual File System (VFS) flags control what actions are permitted on that filesystem: noexec: Do not permit direct execution of any binaries on the mounted filesystem. nosuid: Do not allow set-user-identifier or set-group-identifier bits to take effect.

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Publisher excerpt shortened and converted to plain text. Original source license applies.

Read the full original: [Kubernetes](https://kubernetes.io/blog/2026/09/16/kubernetes-v1-37-hardening-container-storage/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
