Difference between revisions of "Kubernetes Pod Security Standards (PSS)"
Jump to navigation
Jump to search
↑ https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards
Line 1: | Line 1: | ||
* https://kubernetes.io/docs/concepts/security/pod-security-standards/ | * https://kubernetes.io/docs/concepts/security/pod-security-standards/ | ||
− | Pod Security Standards (PSS) and [[Pod Security Admission (PSA)]] define security restrictions for a broad set of workloads since [[Kubernetes v1.23]] (Dec 2021), and replaced [[Pod Security Policies (PSP)]] since [[Kubernetes v1.25]] (Aug 2022). PSS define security levels for workloads. PSAs describe requirements for pod security contexts and related fields. PSAs reference PSS levels to define security restrictions. | + | Pod Security Standards (PSS) and [[Pod Security Admission (PSA)]] define security restrictions for a broad set of workloads since [[Kubernetes v1.23]] (Dec 2021), and replaced [[Pod Security Policies (PSP)]] since [[Kubernetes v1.25]] (Aug 2022). PSS define security levels for workloads. PSAs describe requirements for pod security contexts and related fields. PSAs reference PSS levels to define security restrictions. <ref>https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards</ref> |
+ | |||
Revision as of 08:52, 26 January 2024
Pod Security Standards (PSS) and Pod Security Admission (PSA) define security restrictions for a broad set of workloads since Kubernetes v1.23 (Dec 2021), and replaced Pod Security Policies (PSP) since Kubernetes v1.25 (Aug 2022). PSS define security levels for workloads. PSAs describe requirements for pod security contexts and related fields. PSAs reference PSS levels to define security restrictions. [1]
See also
- Kubernetes security, OPA, EKS security, PSA, PSS, CKS,
SecurityContext
, Trivy, KubeBench, Kubernetes Admission Controllersadmissionregistration.k8s.io
, Hardeneks, Gatekeeper (Kubernetes),kubernetes.io/enforce-mountable-secrets
, Auditing
Advertising: