โŽˆ k8s knowledge compiler

Apply Pod Security Standards at the Namespace Level [page]deterministic

tutorials

This tutorial applies only for new clusters.

Pod Security Admission is an admission controller that applies [Pod Security Standards](/docs/concepts/security/pod-security-standards/) when pods are created. It is a feature GA'ed in v1.25. In this tutorial, you will enforce the `baseline` Pod Security Standard, one namespace at a time.

You can also apply Pod Security Standards to multiple namespaces at once at the cluster level. For instructions, refer to [Apply Pod Security Standards at the cluster level](/docs/tutorials/security/cluster-level-pss/).

##

Install the following on your workstation:

  • [kind](https://kind.sigs.k8s.io/docs/user/quick-start/#installation)
  • [kubectl](/docs/tasks/tools/)

## Create cluster

1. Create a `kind` cluster as follows:

```shell kind create cluster --name psa-ns-level ```

The output is similar to this:

``` Creating cluster "psa-ns-level" ... โœ“ Ensuring node image (kindest/node:v) ๐Ÿ–ผ โœ“ Preparing nodes ๐Ÿ“ฆ โœ“ Writing configuration ๐Ÿ“œ โœ“ Starting control-plane ๐Ÿ•น๏ธ โœ“ Installing CNI ๐Ÿ”Œ โœ“ Installing StorageClass ๐Ÿ’พ Set kubectl context to "kind-psa-ns-level" You can now use your cluster with: kubectl cluster-info --context kind-psa-ns-level Not sure what to do next? ๐Ÿ˜… Check out https://kind.sigs.k8s.io/docs/user/quick-start/ ```

1. Set the kubectl context to the new cluster:

```shell kubectl cluster-info --context kind-psa-ns-level ``` The output is similar to this:

``` Kubernetes control plane is running at https://127.0.0.1:50996 CoreDNS is running at https://127.0.0.1:50996/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'. ```

## Create a namespace

Create a new namespace called `example`:

```shell kubectl create ns example ```

The output is similar to this:

``` namespace/example created ```

## Enable Pod Security Standards checking for that namespace

1. Enable Pod Security Standards on this namespace using labels supported by built-in Pod Security Admission. In this step you will configure a check to warn on Pods that don't meet the latest version of the _baseline_ pod security standard.

```shell kubectl label --overwrite ns example \ pod-security.kubernetes.io/warn=baseline \ pod-security.kubernetes.io/warn-version=latest ```

2. You can configure multiple pod security standard checks on any namespace, using labels. The following command will `enforce` the `baseline` Pod Security Standard, but `warn` and `audit` for `restricted` Pod Security Standards as per the latest version (default value)

```shell kubectl label --overwrite ns example \ pod-security.kubernetes.io/enforce=baseline \ pod-security.kubernetes.io/enforce-version=latest \ pod-security.kubernetes.io/warn=restricted \ pod-security.kubernetes.io/warn-version=latest \ pod-security.kubernetes.io/audit=restricted \ pod-security.kubernetes.io/audit-version=latest ```

## Verify the Pod Security Standard enforcement

1. Create a baseline Pod in the `example` namespace:

```shell kubectl apply -n example -f https://k8s.io/examples/security/example-baseline-pod.yaml ``` The Pod does start OK; the output includes a warning. For example:

``` Warning: would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "nginx" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "nginx" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or container "nginx" must set securityContext.runAsNonRoot=true), seccompProfile (pod or container "nginx" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost") pod/nginx created ```

1. Create a baseline Pod in the `default` namespace:

```shell kubectl apply -n default -f https: โ€ฆ(trimmed)

Sources

tutorials/security/ns-level-pss.md ยท doc โ€” โ€œApply Pod Security Standards at the Namespace Levelโ€

Related (8)

part_of {{% heading "prerequisites" %}} โ€” describes conf=1
part_of Create cluster โ€” describes conf=1
part_of Create a namespace โ€” describes conf=1
part_of Verify the Pod Security Standard enforcement โ€” describes conf=1
part_of Clean up โ€” describes conf=1
part_of {{% heading "whatsnext" %}} โ€” describes conf=1
api_for Namespace โ€” documents API object conf=1

โ† all Docs