🎓 LEVEL 48 DEBRIEF: Pod Security Standards¶
Congratulations! You've mastered Pod Security Standards!
Pod Security Standards¶
Three levels of security enforcement:
1. Privileged (Unrestricted)¶
No restrictions - use with caution!
2. Baseline (Minimal)¶
Prevents known privilege escalations: - No privileged containers - No host path volumes - No host networking
3. Restricted (Hardened)¶
Security best practices (what you just implemented): - ✅ runAsNonRoot: true - ✅ allowPrivilegeEscalation: false - ✅ capabilities dropped - ✅ seccompProfile - ✅ Non-root user
Namespace Labels¶
metadata:
labels:
pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/warn: restricted
- enforce: Blocks non-compliant pods
- audit: Logs violations
- warn: Warns users
Key Takeaways¶
- Restricted = most secure - use in production
- Requires complete SecurityContext - all fields
- Enforced at admission - pods rejected if non-compliant
- Best practice - always run as non-root
- Defense in depth - layer with NetworkPolicy, RBAC
Next Steps¶
- Level 49: PriorityClass
- Level 50: CHAOS FINALE!
Excellent work! 🎉🔒