Back to Practice
Lab

Pod Security Standards

Turn on built-in Pod Security admission: enforce the restricted standard on a namespace, then deploy a workload hardened enough to be admitted under it.

Your mission

Kubernetes ships Pod Security admission built in — no extra controller. You turn it on per namespace with labels, choosing a standard (privileged, baseline, restricted) and a mode (enforce, audit, warn). This is the first line of defence CKS expects you to reach for before writing any custom policy.

You'll enforce the strictest standard, restricted, on the secure-apps namespace (already created), then deploy a workload hardened enough to be admitted under it. A pod that doesn't meet the bar is rejected at creation — so the proof that your workload is compliant is simply that it runs.

kubectl config set-context --current --namespace=secure-apps

Skills you'll put into practice

securitypod-securityadmissioncks

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation