_CORE
AI & Agentic Systems Core Information Systems Cloud & Platform Engineering Data Platform & Integration Security & Compliance QA, Testing & Observability IoT, Automation & Robotics Mobile & Digital Banking & Finance Insurance Public Administration Defense & Security Healthcare Energy & Utilities Telco & Media Manufacturing Logistics & E-commerce Retail & Loyalty
References Technologies Blog Know-how Tools
About Collaboration Careers
CS EN
Let's talk

Pod Security Standards — Kubernetes

17. 05. 2024 1 min read intermediate

Pod Security Standards definují tři úrovně: Privileged (bez omezení), Baseline (minimum), Restricted (nejpřísnější).

Úrovně

  • Privileged: Žádná omezení (development)
  • Baseline: Blokuje known privilege escalations
  • Restricted: Hardened best practices (produkce)

Enforcement

Namespace label

apiVersion: v1 kind: Namespace metadata: name: production labels: pod-security.kubernetes.io/enforce: restricted pod-security.kubernetes.io/warn: restricted pod-security.kubernetes.io/audit: restricted

Key Takeaway

Restricted pro produkci, Baseline minimum. Enforce na namespace úrovni.

securitykubernetespod security
Share:

CORE SYSTEMS tým

Stavíme core systémy a AI agenty, které drží provoz. 15 let zkušeností s enterprise IT.