Lab
Pod Security Standards
Turn on built-in Pod Security admission: enforce the restricted standard on a namespace, then deploy a workload hardened enough to be admitted under it.
Your mission
Kubernetes ships Pod Security admission built in — no extra controller. You turn
it on per namespace with labels, choosing a standard (privileged, baseline,
restricted) and a mode (enforce, audit, warn). This is the first line of
defence CKS expects you to reach for before writing any custom policy.
You'll enforce the strictest standard, restricted, on the secure-apps
namespace (already created), then deploy a workload hardened enough to be admitted
under it. A pod that doesn't meet the bar is rejected at creation — so the proof
that your workload is compliant is simply that it runs.
kubectl config set-context --current --namespace=secure-appsSkills you'll put into practice
securitypod-securityadmissioncks