Pod Security Standards define three security profiles that restrict what pods can do. They replaced PodSecurityPolicy (removed in K8s 1.25) with a simpler, built-in admission controller.
The Three Profiles
| Profile | Purpose | Restrictions |
|---|---|---|
| Privileged | Unrestricted | None — full access |
| Baseline | Minimally restrictive | Blocks known privilege escalations |
| Restricted | Heavily restricted | Best practices enforced |
What Each Profile Blocks
Baseline (prevents obvious exploits)
hostNetwork,hostPID,hostIPC- Privileged containers
- Adding Linux capabilities beyond a safe set
- HostPath volumes
- Host ports
/procmount types
Restricted (production hardening)
Everything in Baseline, plus:
- Must run as non-root
- Must drop ALL capabilities
- Read-only root filesystem
- Seccomp profile required (RuntimeDefault or Localhost)
- No privilege escalation (allowPrivilegeEscalation: false)
Applying Pod Security Standards
Per Namespace
apiVersion: v1
kind: Namespace
metadata:
name: production
labels:
# Enforce: reject pods that violate
pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/enforce-version: latest
# Warn: allow but show warning
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/warn-version: latest
# Audit: log violations
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/audit-version: latest# Apply to existing namespace
kubectl label namespace production \
pod-security.kubernetes.io/enforce=restricted \
pod-security.kubernetes.io/warn=restrictedGradual Rollout Strategy
# Step 1: Audit only (no enforcement)
pod-security.kubernetes.io/audit: restricted
# Step 2: Add warnings (still no enforcement)
pod-security.kubernetes.io/warn: restricted
# Step 3: Enforce after fixing violations
pod-security.kubernetes.io/enforce: restrictedMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Compliant Pod Spec (Restricted)
apiVersion: v1
kind: Pod
metadata:
name: secure-app
spec:
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: app
image: my-app:latest
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
capabilities:
drop:
- ALL
volumeMounts:
- name: tmp
mountPath: /tmp
- name: cache
mountPath: /app/.cache
volumes:
- name: tmp
emptyDir: {}
- name: cache
emptyDir: {}Common Violations and Fixes
Running as Root
# ❌ Violation
containers:
- name: app
image: my-app
# ✅ Fix
containers:
- name: app
image: my-app
securityContext:
runAsNonRoot: true
runAsUser: 1000Update Dockerfile:
FROM node:22-alpine
RUN addgroup -S app && adduser -S app -G app
USER app
WORKDIR /home/app
COPY --chown=app:app . .
CMD ["node", "server.js"]Privilege Escalation
# ❌ Violation (default allows escalation)
containers:
- name: app
# ✅ Fix
containers:
- name: app
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALLWritable Root Filesystem
# ✅ Read-only root + writable tmpfs
containers:
- name: app
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- name: tmp
mountPath: /tmp
- name: logs
mountPath: /app/logs
volumes:
- name: tmp
emptyDir: {}
- name: logs
emptyDir:
sizeLimit: 100MiMissing Seccomp Profile
# ✅ Pod-level seccomp (applies to all containers)
spec:
securityContext:
seccompProfile:
type: RuntimeDefaultNamespace Configuration Matrix
| Namespace | Enforce | Warn | Audit | Why |
|---|---|---|---|---|
kube-system | privileged | baseline | restricted | System components need privileges |
monitoring | baseline | restricted | restricted | Prometheus needs some host access |
production | restricted | restricted | restricted | Full lockdown |
staging | baseline | restricted | restricted | Testing toward restricted |
development | baseline | restricted | restricted | Developer flexibility |
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Checking Compliance
# Dry-run: test a pod against a profile
kubectl label --dry-run=server --overwrite ns production \
pod-security.kubernetes.io/enforce=restricted
# Check audit logs for violations
kubectl get events -A --field-selector reason=FailedCreate
# List namespace security levels
kubectl get namespaces -L \
pod-security.kubernetes.io/enforce,\
pod-security.kubernetes.io/warnHelm Chart Compatibility
Many Helm charts need security context overrides:
# values.yaml
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containerSecurityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
capabilities:
drop:
- ALLWhat's Next?
Our SELinux for System Admins course covers OS-level security that complements Kubernetes Pod Security. Docker Fundamentals teaches container security basics. First lessons are free. -e ---
Ready to go deeper? Explore our hands-on DevOps courses — from Docker and Terraform to MLflow on Kubernetes.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Kubernetes RBAC for Beginners
Kubernetes RBAC from scratch. Roles, ClusterRoles, RoleBindings, ServiceAccounts, and practical examples for access control.
Kubernetes Namespaces Multi-Tenancy
Kubernetes multi-tenancy with namespaces. Resource quotas, limit ranges, network policies, and RBAC for isolating teams.
Kubernetes Network Policies Guide
Secure Kubernetes clusters with network policies. Default deny rules, namespace isolation, pod-level controls, and CNI compatibility.
Kubernetes Pod Troubleshooting
Debug Kubernetes pods systematically. Fix CrashLoopBackOff, ImagePullBackOff, pending pods, and OOMKilled with diagnostic commands.
Kubernetes Probes Liveness Readiness
Configure Kubernetes liveness, readiness, and startup probes. HTTP, TCP, exec checks with proper timing and misconfiguration fixes.
Kubernetes Resource Requests Limits
Set Kubernetes CPU and memory requests and limits correctly. QoS classes, OOMKilled troubleshooting, and VPA right-sizing.
Explore topics
Browse more articles on the topics covered here.