I’m running a Kubernetes environment where one machine acts as an NFS server and several nodes mount the exported directory as read-only.
However, when I create a pod that mounts this NFS directory, the pod is still able to write to the mount, even though the NFS export is configured as read-only.
NFS Server
Server NFS version: 3
Export config (
/etc/exports):
/home/shared-ro 10.141.0.0/16(ro,no_subtree_check,all_squash,async)
Client (Kubernetes node)
NFS client version: 4.2
Mount options from
/etc/fstab:
master:/home/shared-ro /shared-ro nfs4 ro,relatime,vers=4.2,rsize=1048576,wsize=1048576,namlen=255,hard,proto=tcp,timeo=600,retrans=2,sec=sys,clientaddr=10.141.0.2,local_lock=none,addr=10.141.255.254
Important Note
When logging into the node normally (as root or any other user), the mount is correctly read-only — writes fail as expected.
Only Kubernetes pods are able to write, which means Kubernetes is bypassing or overriding the read-only behavior.