What it does. Chooses and applies the correct Kubernetes Pod Security Standard (Privileged, Baseline, Restricted) for a workload: what each profile forbids, how to map existing workloads to a profile, which securityContext fields must change, and how to plan a PodSecurityPolicy-to-PSS migration without breaking running pods. Use when deciding which pod security profile a namespace or workload should run under, auditing which workloads would fail Restricted, planning a PSP migration, or mapping pod security posture to a compliance control. Keywords: Pod Security Standards, PSS, Privileged, Baseline, Restricted, securityContext, runAsNonRoot, drop ALL capabilities, seccomp RuntimeDefault, PSP migration. Do not use for configuring the admission controller that enforces these profiles - use implementing-pod-security-admission-controller. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-kubernetes-pod-security-standards, or copy the skill folder into ~/.claude/skills/implementing-kubernetes-pod-security-standards/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-kubernetes-pod-security-standards/SKILL.md
SKILL.md (verbatim)
name: implementing-kubernetes-pod-security-standards
description: >-
Chooses and applies the correct Kubernetes Pod Security Standard (Privileged,
Baseline, Restricted) for a workload: what each profile forbids, how to map
existing workloads to a profile, which securityContext fields must change, and
how to plan a PodSecurityPolicy-to-PSS migration without breaking running pods.
Use when deciding which pod security profile a namespace or workload should run
under, auditing which workloads would fail Restricted, planning a PSP migration,
or mapping pod security posture to a compliance control. Keywords: Pod Security
Standards, PSS, Privileged, Baseline, Restricted, securityContext, runAsNonRoot,
drop ALL capabilities, seccomp RuntimeDefault, PSP migration. Do not use for
configuring the admission controller that enforces these profiles - use
implementing-pod-security-admission-controller.
domain: cybersecurity
subdomain: container-security
tags:
- containers
- kubernetes
- security
- pod-security
- PSA
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1611
- T1609
- T1525
Implementing Kubernetes Pod Security Standards
Overview
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PSA replaces the deprecated PodSecurityPolicy and provides namespace-level enforcement with three modes: enforce, audit, and warn.
When to Use
- Deciding whether a namespace or workload belongs at Privileged, Baseline, or Restricted
- Auditing which existing workloads would be rejected if Restricted were enforced today
- Translating a "must meet Restricted" requirement into concrete
securityContext changes
- Planning a PodSecurityPolicy migration and predicting what will break before it does
- Mapping pod security posture to a compliance control (NIST PR.PS-01, CIS Kubernetes)
Not this skill: configuring the controller that enforces these profiles — namespace
labels, AdmissionConfiguration, exemptions, or debugging a pod PSA rejected. Use
implementing-pod-security-admission-controller.
Prerequisites
- Kubernetes cluster 1.25+ (PSA GA)
- kubectl configured with cluster-admin access
- Understanding of Linux capabilities and security contexts
Core Concepts
Three Security Profiles
| Profile |
Purpose |
Restrictions |
| Privileged |
Unrestricted, system workloads |
None |
| Baseline |
Prevents known escalations |
No hostNetwork, hostPID, hostIPC, privileged containers, dangerous capabilities |
| Restricted |
Hardened best practices |
Non-root, drop ALL caps, seccomp required, read-only rootfs recommended |
Three Enforcement Modes
| Mode |
Behavior |
| enforce |
Rejects pods that violate the policy |
| audit |
Logs violations in audit log but allows pod |
| warn |
Returns warning to user but allows pod |
Workflow
Step 1: Label Namespaces for PSA
# Restricted namespace - production workloads
apiVersion: v1
kind: Namespace
metadata:
name: production
labels:
pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/enforce-version: latest
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/audit-version: latest
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/warn-version: latest
# Baseline namespace - general workloads
apiVersion: v1
kind: Namespace
metadata:
name: staging
labels:
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/enforce-version: latest
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/audit-version: latest
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/warn-version: latest
# Privileged namespace - system components only
apiVersion: v1
kind: Namespace
metadata:
name: kube-system
labels:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/enforce-version: latest
Step 2: Apply Labels to Existing Namespaces
# Apply restricted enforcement to production
kubectl label namespace production \
pod-security.kubernetes.io/enforce=restricted \
pod-security.kubernetes.io/audit=restricted \
pod-security.kubernetes.io/warn=restricted \
--overwrite
# Apply baseline to staging with restricted warnings
kubectl label namespace staging \
pod-security.kubernetes.io/enforce=baseline \
pod-security.kubernetes.io/audit=restricted \
pod-security.kubernetes.io/warn=restricted \
--overwrite
# Check labels on all namespaces
kubectl get namespaces -L pod-security.kubernetes.io/enforce
Step 3: Create Compliant Pod Specs
# Restricted-compliant deployment
apiVersion: apps/v1
kind: Deployment
metadata:
name: secure-app
namespace: production
spec:
replicas: 3
selector:
matchLabels:
app: secure-app
template:
metadata:
labels:
app: secure-app
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 65534
runAsGroup: 65534
fsGroup: 65534
seccompProfile:
type: RuntimeDefault
containers:
- name: app
image: myregistry.com/myapp:v1.0.0@sha256:abc123
ports:
- containerPort: 8080
protocol: TCP
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
runAsNonRoot: true
runAsUser: 65534
resources:
requests:
memory: "64Mi"
cpu: "100m"
limits:
memory: "256Mi"
cpu: "500m"
volumeMounts:
- name: tmp
mountPath: /tmp
- name: cache
mountPath: /var/cache
volumes:
- name: tmp
emptyDir:
sizeLimit: 100Mi
- name: cache
emptyDir:
sizeLimit: 50Mi
Step 4: Gradual Migration Strategy
# Phase 1: Audit mode - discover violations without blocking
kubectl label namespace my-namespace \
pod-security.kubernetes.io/audit=restricted \
pod-security.kubernetes.io/warn=restricted
# Check audit logs for violations
kubectl logs -n kube-system -l component=kube-apiserver | grep "pod-security"
# Phase 2: Enforce baseline, warn on restricted
kubectl label namespace my-namespace \
pod-security.kubernetes.io/enforce=baseline \
pod-security.kubernetes.io/warn=restricted \
--overwrite
# Phase 3: Full restricted enforcement
kubectl label namespace my-namespace \
pod-security.kubernetes.io/enforce=restricted \
--overwrite
Step 5: Dry-Run Enforcement Testing
# Test what would happen with restricted enforcement
kubectl label --dry-run=server --overwrite namespace my-namespace \
pod-security.kubernetes.io/enforce=restricted
# Example output:
# Warning: existing pods in namespace "my-namespace" violate the new
# PodSecurity enforce level "restricted:latest"
# Warning: nginx-xxx: allowPrivilegeEscalation != false,
# unrestricted capabilities, runAsNonRoot != true, seccompProfile
Baseline Profile Restrictions
| Control |
Restricted |
Requirement |
| HostProcess |
Must not set |
Pods cannot use Windows HostProcess |
| Host Namespaces |
Must not set |
No hostNetwork, hostPID, hostIPC |
| Privileged |
Must not set |
No privileged: true |
| Capabilities |
Baseline list only |
Only NET_BIND_SERVICE, drop ALL for restricted |
| HostPath Volumes |
Must not use |
No hostPath volume mounts |
| Host Ports |
Must not use |
No hostPort in container spec |
| AppArmor |
Default/runtime |
Cannot set to unconfined |
| SELinux |
Limited types |
Only container_t, container_init_t, container_kvm_t |
| /proc Mount Type |
Default only |
Must use Default proc mount |
| Seccomp |
RuntimeDefault or Localhost |
Must specify seccomp profile (restricted) |
| Sysctls |
Safe set only |
Limited to safe sysctls |
Validation Commands
# Verify namespace labels
kubectl get ns --show-labels | grep pod-security
# Test pod creation against policy
kubectl run test-pod --image=nginx --namespace=production --dry-run=server
# Check for violations in audit logs
kubectl get events --field-selector reason=FailedCreate -A
# Scan with Kubescape for PSS compliance
kubescape scan framework nsa --namespace production
References
Other files in this skill
assets/template.md (verbatim)
Pod Security Standards Implementation Template
Namespace Classification
| Namespace |
Current PSS Level |
Target PSS Level |
Migration Status |
| kube-system |
privileged |
privileged |
N/A |
| production |
|
restricted |
|
| staging |
|
baseline |
|
| development |
|
baseline |
|
PSS Label Configuration
| Namespace |
enforce |
audit |
warn |
Version |
|
|
|
|
latest |
Workload Compliance Checklist
Pod Security Context
Container Security Context
Pod Spec
Migration Plan
| Phase |
Action |
Timeline |
Status |
| 1 |
Apply audit+warn labels |
Week 1 |
|
| 2 |
Review audit violations |
Week 2-3 |
|
| 3 |
Fix workload security contexts |
Week 4-6 |
|
| 4 |
Enable baseline enforce |
Week 7 |
|
| 5 |
Enable restricted enforce |
Week 8 |
|
Exceptions
| Namespace |
Workload |
Required Level |
Justification |
Approved By |
|
|
|
|
|
references/api-reference.md (verbatim)
API Reference: Implementing Kubernetes Pod Security Standards
PSA Namespace Labels
# Apply restricted enforcement
kubectl label namespace production \
pod-security.kubernetes.io/enforce=restricted \
pod-security.kubernetes.io/audit=restricted \
pod-security.kubernetes.io/warn=restricted --overwrite
Pod Security Standard Levels
| Level |
Description |
Blocks |
| Privileged |
Unrestricted |
Nothing |
| Baseline |
Minimally restrictive |
hostNetwork, privileged, hostPID/IPC |
| Restricted |
Heavily restricted |
+ runAsNonRoot, drop ALL caps, seccomp |
PSA Modes
| Mode |
Behavior |
| enforce |
Reject violating pods |
| audit |
Log violations (allow pod) |
| warn |
Warn user (allow pod) |
Baseline Violations
| Field |
Forbidden Value |
spec.hostNetwork |
true |
spec.hostPID |
true |
spec.hostIPC |
true |
containers[*].securityContext.privileged |
true |
containers[*].securityContext.capabilities.add |
Non-default |
Restricted Violations (adds to Baseline)
| Field |
Required |
runAsNonRoot |
true |
allowPrivilegeEscalation |
false |
capabilities.drop |
["ALL"] |
seccompProfile.type |
RuntimeDefault or Localhost |
References
references/standards.md (verbatim)
Standards Reference - Kubernetes Pod Security Standards
Kubernetes Pod Security Standards (PSS) v1.31
Privileged Profile
- No restrictions applied
- Used for: kube-system, monitoring agents, CNI plugins, storage drivers
Baseline Profile Controls
| Control |
Policy |
| HostProcess |
Must be false |
| Host Namespaces |
hostNetwork, hostPID, hostIPC must be false |
| Privileged Containers |
Must be false |
| Capabilities |
Cannot add beyond: AUDIT_WRITE, CHOWN, DAC_OVERRIDE, FOWNER, FSETID, KILL, MKNOD, NET_BIND_SERVICE, SETFCAP, SETGID, SETPCAP, SETUID, SYS_CHROOT |
| HostPath Volumes |
Must not be used |
| Host Ports |
Must not define hostPort |
| AppArmor |
Must not set to unconfined |
| SELinux |
type must be container_t, container_init_t, or container_kvm_t; user/role must not be set |
| /proc Mount Type |
Must be Default |
| Seccomp |
Must not set to Unconfined |
| Sysctls |
Must only use safe sysctls |
Restricted Profile Controls (in addition to Baseline)
| Control |
Policy |
| Volume Types |
Only: configMap, csi, downwardAPI, emptyDir, ephemeral, persistentVolumeClaim, projected, secret |
| Privilege Escalation |
allowPrivilegeEscalation must be false |
| Running as Non-root |
runAsNonRoot must be true |
| Running as Non-root User |
runAsUser must be non-zero |
| Seccomp |
Must be RuntimeDefault or Localhost |
| Capabilities |
Must drop ALL; may only add NET_BIND_SERVICE |
CIS Kubernetes Benchmark v1.8
Section 5: Policies
- 5.1: RBAC and Service Accounts
- 5.2: Pod Security Standards
- 5.2.1: Ensure PSA is not set to Privileged on non-system namespaces
- 5.2.2: Minimize admission of privileged containers
- 5.2.3: Minimize admission of containers wanting to share host process ID namespace
- 5.2.4: Minimize admission of containers wanting to share host IPC namespace
- 5.2.5: Minimize admission of containers wanting to share host network namespace
- 5.2.6: Minimize admission of containers with allowPrivilegeEscalation
- 5.2.7: Minimize admission of root containers
- 5.2.8: Minimize admission of containers with NET_RAW capability
- 5.2.9: Minimize admission of containers with added capabilities
- 5.2.10: Minimize admission of containers with capabilities assigned
- 5.2.11: Minimize admission of containers with HostProcess
- 5.2.12: Minimize admission of HostPath volumes
- 5.2.13: Minimize admission of containers with unrestricted Seccomp profile
NSA/CISA Kubernetes Hardening Guide
Pod Security Recommendations
- Use PSA in enforce mode for production namespaces
- Set restricted profile as default for all non-system namespaces
- Require seccomp profiles on all pods
- Prevent privileged containers in all workload namespaces
- Require non-root user for all containers
- Drop all capabilities and only add NET_BIND_SERVICE if needed
MITRE ATT&CK for Containers
Techniques Prevented by Restricted Profile
| Technique |
PSS Control |
| T1611 - Escape to Host |
Blocks privileged, hostPID, hostNetwork |
| T1610 - Deploy Container |
Blocks privileged containers |
| T1053 - Scheduled Task |
Blocks host namespace access |
| T1548 - Abuse Elevation Control |
Blocks allowPrivilegeEscalation |
references/workflows.md (verbatim)
Workflows - Kubernetes Pod Security Standards
Workflow 1: PSS Migration from PodSecurityPolicy
[Identify PSP usage] --> [Map PSP to PSS levels] --> [Apply audit/warn labels]
| | |
v v v
kubectl get psp Privileged PSP -> baseline Monitor audit logs
List all namespaces Restrictive PSP -> restricted for 2-4 weeks
| | |
+------------------------+---------------------------+
|
v
[Enable enforce mode per namespace]
|
v
[Remove PodSecurityPolicy resources]
|
v
[Disable PSP admission controller]
Workflow 2: New Namespace Onboarding
Step 1: Classify workload sensitivity
- System/Infrastructure -> Privileged (only kube-system)
- General workloads -> Baseline + Restricted warnings
- Production/Sensitive -> Restricted enforce
Step 2: Create namespace with labels
kubectl create namespace $NS
kubectl label namespace $NS \
pod-security.kubernetes.io/enforce=$LEVEL \
pod-security.kubernetes.io/audit=restricted \
pod-security.kubernetes.io/warn=restricted
Step 3: Test with dry-run
kubectl run test --image=nginx -n $NS --dry-run=server
Step 4: Deploy workloads with compliant security contexts
Step 5: Validate enforcement
kubectl get events -n $NS --field-selector reason=FailedCreate
Workflow 3: CI/CD PSS Compliance Check
# Pre-deployment validation
name: PSS Compliance Check
on: pull_request
jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install kubescape
run: curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash
- name: Scan manifests for PSS restricted compliance
run: |
kubescape scan framework nsa \
--controls-config controls.json \
--format junit --output results.xml \
k8s-manifests/
- name: Validate security contexts
run: |
for file in k8s-manifests/*.yaml; do
echo "Checking $file..."
# Verify runAsNonRoot
if ! grep -q "runAsNonRoot: true" "$file"; then
echo "FAIL: Missing runAsNonRoot in $file"
exit 1
fi
# Verify drop ALL
if ! grep -q "drop:" "$file" || ! grep -A1 "drop:" "$file" | grep -q "ALL"; then
echo "FAIL: Missing drop ALL capabilities in $file"
exit 1
fi
done
Workflow 4: Violation Response
[PSA Violation Detected]
|
+-- enforce mode --> Pod rejected --> Alert developer
| |
| v
| Fix security context
| Re-deploy
|
+-- audit mode --> Pod allowed, audit log entry
| |
| v
| Weekly audit review
| Create remediation ticket
|
+-- warn mode --> Pod allowed, user warning
|
v
Developer sees warning
Fix before enforce rollout
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.