Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions
Kubernetes 1.37 adds emptyDir permission modes and bind‑mount flags (noexec, nosuid, nodev) to let developers enforce stricter storage policies directly in the platform. The blog details the Linux fundamentals, usage examples, and how the defaults previously allowed writable volumes to execute arbitrary binaries, improving workload hardening.