Pod Security Admission

The Pod Security Admission Controller

The built-in Pod Security admission controller (stable since 1.25) applies a standard per namespace, set by labels, in three modes: enforce rejects violating Pods, warn warns the client, and audit annotates the audit log. A server-side dry run shows what a level would break before you set it:

Testing BookNest against the restricted levelShell
kubectl label --dry-run=server --overwrite namespace booknest \
  pod-security.kubernetes.io/enforce=restricted 2>&1 | fold -s -w 90
Output
Warning: existing pods in namespace "booknest" violate the new PodSecurity enforce level
"restricted:latest"
Warning: api-b4bc995c9-85vbt (and 1 other pod): unrestricted capabilities, seccompProfile
Warning: db-init-cwlpv (and 4 other pods): allowPrivilegeEscalation != false,
unrestricted capabilities, runAsNonRoot != true, seccompProfile
namespace/booknest labeled (server dry run)

The API lacks only a capability drop and a seccomp profile, but the official PostgreSQL 1,289 and Nginx 75 images start as root. So k8s/namespace.yaml gains four labels: pod-security.kubernetes.io/enforce: baseline, enforce-version: v1.37 (so an upgrade cannot tighten it unannounced), and warn and audit set to restricted, the goal:

Enforcing baseline: a privileged Pod is rejected, a plain one warnedShell
kubectl apply -f k8s/namespace.yaml | grep namespace
kubectl run root-shell --image=localhost:33500/booknest-web:1.3 --privileged 2>&1 \
  | fold -s -w 90
kubectl run plain --image=localhost:33500/booknest-web:1.3 2>&1 | fold -s -w 90
kubectl delete pod plain >/dev/null
git commit -qam "Enforce the baseline Pod Security Standard on booknest"
Output
namespace/booknest configured
Error from server (Forbidden): pods "root-shell" is forbidden: violates PodSecurity
"baseline:v1.37": privileged (container "root-shell" must not set
securityContext.privileged=true)
Warning: would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false
...
pod/plain created

Warnings also fire for Deployments and other Pod templates, before any Pod fails. For rules the standards cannot express, such as allowed registries, add ValidatingAdmissionPolicy (built in, CEL, stable since 1.30), Kyverno 223,283 or OPA Gatekeeper 126 .