Difference between revisions of "Kubernetes Pod Security Standards (PSS)"
Jump to navigation
Jump to search
↑ https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards
(5 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
* https://kubernetes.io/docs/concepts/security/pod-security-standards/ | * https://kubernetes.io/docs/concepts/security/pod-security-standards/ | ||
− | Pod Security Standards (PSS) and [[Pod Security Admission (PSA)]] define security restrictions for a broad set of workloads since [[Kubernetes v1.23]], and replaced [[Pod Security Policies (PSP)]] since [[Kubernetes v1.25]]. | + | Pod Security Standards (PSS) and [[Pod Security Admission (PSA)]] define security restrictions for a broad set of workloads since [[Kubernetes v1.23]] (Dec 2021), and replaced [[Pod Security Policies (PSP)]] since [[Kubernetes v1.25]] (Aug 2022). PSS define security levels for workloads. PSAs describe requirements for pod security contexts and related fields. PSAs reference PSS levels to define security restrictions. <ref>https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards</ref> |
+ | == Related == | ||
* [[Pod Security Admission (PSA)]] | * [[Pod Security Admission (PSA)]] | ||
+ | * <code>[[global.cattle.psp.enabled]]</code> | ||
== See also == | == See also == |
Latest revision as of 08:53, 26 January 2024
Pod Security Standards (PSS) and Pod Security Admission (PSA) define security restrictions for a broad set of workloads since Kubernetes v1.23 (Dec 2021), and replaced Pod Security Policies (PSP) since Kubernetes v1.25 (Aug 2022). PSS define security levels for workloads. PSAs describe requirements for pod security contexts and related fields. PSAs reference PSS levels to define security restrictions. [1]
Related[edit]
See also[edit]
- Kubernetes security, OPA, EKS security, PSA, PSS, CKS,
SecurityContext
, Trivy, KubeBench, Kubernetes Admission Controllersadmissionregistration.k8s.io
, Hardeneks, Gatekeeper (Kubernetes),kubernetes.io/enforce-mountable-secrets
, Auditing
Advertising: