Kubernetes pod can write to NFS mount even though the export is read-only (NFSv3 server, NFSv4.2 client)
09:33 14 Nov 2025

I’m running a Kubernetes environment where one machine acts as an NFS server and several nodes mount the exported directory as read-only.
However, when I create a pod that mounts this NFS directory, the pod is still able to write to the mount, even though the NFS export is configured as read-only.

NFS Server

  • Server NFS version: 3

  • Export config (/etc/exports):

/home/shared-ro  10.141.0.0/16(ro,no_subtree_check,all_squash,async)

Client (Kubernetes node)

  • NFS client version: 4.2

  • Mount options from /etc/fstab:

master:/home/shared-ro /shared-ro nfs4 ro,relatime,vers=4.2,rsize=1048576,wsize=1048576,namlen=255,hard,proto=tcp,timeo=600,retrans=2,sec=sys,clientaddr=10.141.0.2,local_lock=none,addr=10.141.255.254

Important Note

When logging into the node normally (as root or any other user), the mount is correctly read-only — writes fail as expected.
Only Kubernetes pods are able to write, which means Kubernetes is bypassing or overriding the read-only behavior.

kubernetes root volume containerd nfsclient