Thanks for getting back.
Your environment seems pretty similar to store the Volumes (bind mounts) in the /root directory.
Or using aCIFS share like I was talking on this topic (mounting it as file_mode=0700,dir_mode=0700).
Correct.
At least per the default settings.
Indeed, I was taking a look but it may not worth the complexity.
That seems a rule valid for everything running as root that can be run as with lower permissions.