Apply Pod Security Standards at the Namespace Level [page]deterministic
This tutorial applies only for new clusters.
Pod Security Admission is an admission controller that applies [Pod Security Standards](/docs/concepts/security/pod-security-standards/) when pods are created. It is a feature GA'ed in v1.25. In this tutorial, you will enforce the `baseline` Pod Security Standard, one namespace at a time.
You can also apply Pod Security Standards to multiple namespaces at once at the cluster level. For instructions, refer to [Apply Pod Security Standards at the cluster level](/docs/tutorials/security/cluster-level-pss/).
##
Install the following on your workstation:
- [kind](https://kind.sigs.k8s.io/docs/user/quick-start/#installation)
- [kubectl](/docs/tasks/tools/)
## Create cluster
1. Create a `kind` cluster as follows:
```shell kind create cluster --name psa-ns-level ```
The output is similar to this:
``` Creating cluster "psa-ns-level" ... โ Ensuring node image (kindest/node:v) ๐ผ โ Preparing nodes ๐ฆ โ Writing configuration ๐ โ Starting control-plane ๐น๏ธ โ Installing CNI ๐ โ Installing StorageClass ๐พ Set kubectl context to "kind-psa-ns-level" You can now use your cluster with: kubectl cluster-info --context kind-psa-ns-level Not sure what to do next? ๐ Check out https://kind.sigs.k8s.io/docs/user/quick-start/ ```
1. Set the kubectl context to the new cluster:
```shell kubectl cluster-info --context kind-psa-ns-level ``` The output is similar to this:
``` Kubernetes control plane is running at https://127.0.0.1:50996 CoreDNS is running at https://127.0.0.1:50996/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'. ```
## Create a namespace
Create a new namespace called `example`:
```shell kubectl create ns example ```
The output is similar to this:
``` namespace/example created ```
## Enable Pod Security Standards checking for that namespace
1. Enable Pod Security Standards on this namespace using labels supported by built-in Pod Security Admission. In this step you will configure a check to warn on Pods that don't meet the latest version of the _baseline_ pod security standard.
```shell kubectl label --overwrite ns example \ pod-security.kubernetes.io/warn=baseline \ pod-security.kubernetes.io/warn-version=latest ```
2. You can configure multiple pod security standard checks on any namespace, using labels. The following command will `enforce` the `baseline` Pod Security Standard, but `warn` and `audit` for `restricted` Pod Security Standards as per the latest version (default value)
```shell kubectl label --overwrite ns example \ pod-security.kubernetes.io/enforce=baseline \ pod-security.kubernetes.io/enforce-version=latest \ pod-security.kubernetes.io/warn=restricted \ pod-security.kubernetes.io/warn-version=latest \ pod-security.kubernetes.io/audit=restricted \ pod-security.kubernetes.io/audit-version=latest ```
## Verify the Pod Security Standard enforcement
1. Create a baseline Pod in the `example` namespace:
```shell kubectl apply -n example -f https://k8s.io/examples/security/example-baseline-pod.yaml ``` The Pod does start OK; the output includes a warning. For example:
``` Warning: would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "nginx" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "nginx" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or container "nginx" must set securityContext.runAsNonRoot=true), seccompProfile (pod or container "nginx" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost") pod/nginx created ```
1. Create a baseline Pod in the `default` namespace:
```shell kubectl apply -n default -f https: โฆ(trimmed)