Urgent.News

What's breaking now, across thousands of outlets.

Tech

Enforce the baseline Pod Security Standard on a namespace (CKS)

Enforce the baseline Pod Security Standard on a namespace (CKS) Lesson four of the CKS series: Pod Security Standards. One of the pods in our namespace can read the logs of every other pod on its node, including the control plane's. We will shut that down with a single namespace label, preview the impact before we apply it, and capture the exact reason the pod can never come back. ๐ŸŽฅ Watch theโ€ฆ

In this lesson of the CKS series, you will learn how to enforce the baseline Pod Security Standard on a namespace. One pod in the namespace can access the logs of every other pod on its node, including those of the control plane. To address this security concern, you will label the namespace, preview the impact, and save the event explaining why the pod cannot be recreated.

Pod Security Admission is built into every Kubernetes cluster and can be configured with namespace labels. There are three standards: Privileged allows anything, Baseline blocks known escapes like hostPath volumes, host networking, and privileged containers, and Restricted demands running as non-root. The label pod-security.kubernetes.io/enforce determines what gets rejected. There are also audit and warn modes that only report violations.

In the scenario, you have a Deployment called node-inspector that mounts the node's /var/log/pods folder through a hostPath volume. You will enforce the baseline Pod Security Standard on the namespace, delete the running node-inspector pod, and save the event explaining why it cannot be recreated to pss-denial.log.

Pod Security Admission runs when a pod is created, and already running pods are left alone. The task instructs you to delete the node-inspector pod yourself because Kubernetes won't kill a running workload due to a label change. After applying the baseline enforcement, you will see that node-inspector is still running because enforcement happens at admission, not when a label changes.

To preview the impact, you can use a dry run command with --dry-run=server, which warns about violating the new PodSecurity enforce level and lists the violated pod. Once you're satisfied with the preview, you can enforce the baseline by applying the label to the namespace. The node-inspector pod will still be running because enforcement occurs at admission time.

To delete the node-inspector pod, you can use the kubectl delete command. After deletion, you can verify that the pod has been removed using the kubectl get pods command. Finally, you can save the reason for the pod's failure using the kubectl describe command on the ReplicaSet and save the event with reason FailedCreate to a file named pss-denial.log.

Written by urgent.news from Dev.to's reporting โ€” not their text. Machine-written โ€” may contain errors; check the original before relying on it.

Read the original at dev.to โ†’

More in Tech

Day 7 of Building Crowdwide โ€” UI Polishing, My First Advertiser, and Translation Breaking AGAIN ๐Ÿ˜ญ

First of all, THANK YOU for this progress and reading my articles! โค๏ธ Welcome back to another update on building Crowdwide , my social platform! A lot has happened since my last update.

  • Crowdwide has seven members, 35 posts, and two advertisers
  • First external advertiser approved with insufficient Waves
  • Harun (@koda2026) joins moderator team to assist platform management

Why Can't My App Connect to My Database?

A beginner's guide to the 4 checks on AWS The big idea first When your app connects to a database, the connection has to pass 4 checks, one after another . If any one fails, the connection fails.

  • Security Group blocks incoming traffic by default
  • PostgreSQL must listen for external connections
  • pghba.conf grants specific user access

More from Friday 9 October โ†’