The built-in Pod Security admission controller (stable since 1.25) applies a standard per namespace, set by labels, in three modes: enforce rejects violating Pods, warn warns the client, and audit annotates the audit log. A server-side dry run shows what a level would break before you set it:
kubectl label --dry-run=server --overwrite namespace booknest \
pod-security.kubernetes.io/enforce=restricted 2>&1 | fold -s -w 90Warning: existing pods in namespace "booknest" violate the new PodSecurity enforce level "restricted:latest" Warning: api-b4bc995c9-85vbt (and 1 other pod): unrestricted capabilities, seccompProfile Warning: db-init-cwlpv (and 4 other pods): allowPrivilegeEscalation != false, unrestricted capabilities, runAsNonRoot != true, seccompProfile namespace/booknest labeled (server dry run)
The API lacks only a capability drop and a seccomp profile, but the official PostgreSQL 1,289 and Nginx 75 images start as root. So k8s/namespace.yaml gains four labels: pod-security.kubernetes.io/enforce: baseline, enforce-version: v1.37 (so an upgrade cannot tighten it unannounced), and warn and audit set to restricted, the goal:
kubectl apply -f k8s/namespace.yaml | grep namespace
kubectl run root-shell --image=localhost:33500/booknest-web:1.3 --privileged 2>&1 \
| fold -s -w 90
kubectl run plain --image=localhost:33500/booknest-web:1.3 2>&1 | fold -s -w 90
kubectl delete pod plain >/dev/null
git commit -qam "Enforce the baseline Pod Security Standard on booknest"namespace/booknest configured Error from server (Forbidden): pods "root-shell" is forbidden: violates PodSecurity "baseline:v1.37": privileged (container "root-shell" must not set securityContext.privileged=true) Warning: would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false ... pod/plain created
Warnings also fire for Deployments and other Pod templates, before any Pod fails. For rules the standards cannot express, such as allowed registries, add ValidatingAdmissionPolicy (built in, CEL, stable since 1.30), Kyverno 223,283 or OPA Gatekeeper 126 .