Skip to content

🎓 LEVEL 48 DEBRIEF: Pod Security Standards

Congratulations! You've mastered Pod Security Standards!


Pod Security Standards

Three levels of security enforcement:

1. Privileged (Unrestricted)

No restrictions - use with caution!

2. Baseline (Minimal)

Prevents known privilege escalations: - No privileged containers - No host path volumes - No host networking

3. Restricted (Hardened)

Security best practices (what you just implemented): - ✅ runAsNonRoot: true - ✅ allowPrivilegeEscalation: false - ✅ capabilities dropped - ✅ seccompProfile - ✅ Non-root user


Namespace Labels

metadata:
  labels:
    pod-security.kubernetes.io/enforce: restricted
    pod-security.kubernetes.io/audit: restricted
    pod-security.kubernetes.io/warn: restricted
  • enforce: Blocks non-compliant pods
  • audit: Logs violations
  • warn: Warns users

Key Takeaways

  1. Restricted = most secure - use in production
  2. Requires complete SecurityContext - all fields
  3. Enforced at admission - pods rejected if non-compliant
  4. Best practice - always run as non-root
  5. Defense in depth - layer with NetworkPolicy, RBAC

Next Steps

  • Level 49: PriorityClass
  • Level 50: CHAOS FINALE!

Excellent work! 🎉🔒