โŽˆ k8s knowledge compiler

Apply Pod Security Standards at the Cluster Level [page]deterministic

tutorials

This tutorial applies only for new clusters.

Pod Security is an admission controller that carries out checks against the Kubernetes [Pod Security Standards](/docs/concepts/security/pod-security-standards/) when new pods are created. It is a feature GA'ed in v1.25. This tutorial shows you how to enforce the `baseline` Pod Security Standard at the cluster level which applies a standard configuration to all namespaces in a cluster.

To apply Pod Security Standards to specific namespaces, refer to [Apply Pod Security Standards at the namespace level](/docs/tutorials/security/ns-level-pss).

If you are running a version of Kubernetes other than v, check the documentation for that version.

##

Install the following on your workstation:

  • [kind](https://kind.sigs.k8s.io/docs/user/quick-start/#installation)
  • [kubectl](/docs/tasks/tools/)

This tutorial demonstrates what you can configure for a Kubernetes cluster that you fully control. If you are learning how to configure Pod Security Admission for a managed cluster where you are not able to configure the control plane, read [Apply Pod Security Standards at the namespace level](/docs/tutorials/security/ns-level-pss).

## Choose the right Pod Security Standard to apply

[Pod Security Admission](/docs/concepts/security/pod-security-admission/) lets you apply built-in [Pod Security Standards](/docs/concepts/security/pod-security-standards/) with the following modes: `enforce`, `audit`, and `warn`.

To gather information that helps you to choose the Pod Security Standards that are most appropriate for your configuration, do the following:

1. Create a cluster with no Pod Security Standards applied:

```shell kind create cluster --name psa-wo-cluster-pss ``` The output is similar to: ``` Creating cluster "psa-wo-cluster-pss" ... โœ“ Ensuring node image (kindest/node:v) ๐Ÿ–ผ โœ“ Preparing nodes ๐Ÿ“ฆ โœ“ Writing configuration ๐Ÿ“œ โœ“ Starting control-plane ๐Ÿ•น๏ธ โœ“ Installing CNI ๐Ÿ”Œ โœ“ Installing StorageClass ๐Ÿ’พ Set kubectl context to "kind-psa-wo-cluster-pss" You can now use your cluster with:

kubectl cluster-info --context kind-psa-wo-cluster-pss

Thanks for using kind! ๐Ÿ˜Š ```

1. Set the kubectl context to the new cluster:

```shell kubectl cluster-info --context kind-psa-wo-cluster-pss ``` The output is similar to this:

``` Kubernetes control plane is running at https://127.0.0.1:61350

CoreDNS is running at https://127.0.0.1:61350/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy

To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'. ```

1. Get a list of namespaces in the cluster:

```shell kubectl get ns ``` The output is similar to this: ``` NAME STATUS AGE default Active 9m30s kube-node-lease Active 9m32s kube-public Active 9m32s kube-system Active 9m32s local-path-storage Active 9m26s ```

1. Use `--dry-run=server` to understand what happens when different Pod Security Standards are applied:

1. Privileged ```shell kubectl label --dry-run=server --overwrite ns --all \ pod-security.kubernetes.io/enforce=privileged ```

The output is similar to: ``` namespace/default labeled namespace/kube-node-lease labeled namespace/kube-public labeled namespace/kube-system labeled namespace/local-path-storage labeled ``` 2. Baseline ```shell kubectl label --dry-run=server --overwrite ns --all \ pod-security.kubernetes.io/enforce=baseline ```

The output is similar to: ``` namespace/default labeled namespace/kube-node-lease labeled namespace/kube-public labeled Warning: existing pods in namespace "kube-system" violate the new PodSecurity enforce level "baseline:latest" Warning: etcd-psa-wo-cluster-pss-control-plane (and 3 other pods): host namespaces, hostPa โ€ฆ(trimmed)

Sources

tutorials/security/cluster-level-pss.md ยท doc โ€” โ€œApply Pod Security Standards at the Cluster Levelโ€

Related (6)

part_of {{% heading "prerequisites" %}} โ€” describes conf=1
part_of Choose the right Pod Security Standard to apply โ€” describes conf=1
part_of Set modes, versions and standards โ€” describes conf=1
part_of Clean up โ€” describes conf=1
part_of {{% heading "whatsnext" %}} โ€” describes conf=1
api_for Pod โ€” documents API object conf=1

โ† all Docs