implementing-kubernetes-pod-security-standards skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Chooses and applies the correct Kubernetes Pod Security Standard (Privileged, Baseline, Restricted) for a workload: what each profile forbids, how to map existing workloads to a profile, which securityContext fields must change, and how to plan a PodSecurityPolicy-to-PSS migration without breaking running pods. Use when deciding which pod security profile a namespace or workload should run under, auditing which workloads would fail Restricted, planning a PSP migration, or mapping pod security posture to a compliance control. Keywords: Pod Security Standards, PSS, Privileged, Baseline, Restricted, securityContext, runAsNonRoot, drop ALL capabilities, seccomp RuntimeDefault, PSP migration. Do not use for configuring the admission controller that enforces these profiles - use implementing-pod-security-admission-controller. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-kubernetes-pod-security-standards/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-kubernetes-pod-security-standards, or copy the skill folder into ~/.claude/skills/implementing-kubernetes-pod-security-standards/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-kubernetes-pod-security-standards/SKILL.md

SKILL.md (verbatim)

name: implementing-kubernetes-pod-security-standards
description: >-
  Chooses and applies the correct Kubernetes Pod Security Standard (Privileged,
  Baseline, Restricted) for a workload: what each profile forbids, how to map
  existing workloads to a profile, which securityContext fields must change, and
  how to plan a PodSecurityPolicy-to-PSS migration without breaking running pods.
  Use when deciding which pod security profile a namespace or workload should run
  under, auditing which workloads would fail Restricted, planning a PSP migration,
  or mapping pod security posture to a compliance control. Keywords: Pod Security
  Standards, PSS, Privileged, Baseline, Restricted, securityContext, runAsNonRoot,
  drop ALL capabilities, seccomp RuntimeDefault, PSP migration. Do not use for
  configuring the admission controller that enforces these profiles - use
  implementing-pod-security-admission-controller.
domain: cybersecurity
subdomain: container-security
tags:
- containers
- kubernetes
- security
- pod-security
- PSA
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
mitre_attack:
- T1610
- T1611
- T1609
- T1525

Implementing Kubernetes Pod Security Standards

Overview

Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PSA replaces the deprecated PodSecurityPolicy and provides namespace-level enforcement with three modes: enforce, audit, and warn.

When to Use

  • Deciding whether a namespace or workload belongs at Privileged, Baseline, or Restricted
  • Auditing which existing workloads would be rejected if Restricted were enforced today
  • Translating a "must meet Restricted" requirement into concrete securityContext changes
  • Planning a PodSecurityPolicy migration and predicting what will break before it does
  • Mapping pod security posture to a compliance control (NIST PR.PS-01, CIS Kubernetes)

Not this skill: configuring the controller that enforces these profiles — namespace labels, AdmissionConfiguration, exemptions, or debugging a pod PSA rejected. Use implementing-pod-security-admission-controller.

Prerequisites

  • Kubernetes cluster 1.25+ (PSA GA)
  • kubectl configured with cluster-admin access
  • Understanding of Linux capabilities and security contexts

Core Concepts

Three Security Profiles

Profile Purpose Restrictions
Privileged Unrestricted, system workloads None
Baseline Prevents known escalations No hostNetwork, hostPID, hostIPC, privileged containers, dangerous capabilities
Restricted Hardened best practices Non-root, drop ALL caps, seccomp required, read-only rootfs recommended

Three Enforcement Modes

Mode Behavior
enforce Rejects pods that violate the policy
audit Logs violations in audit log but allows pod
warn Returns warning to user but allows pod

Workflow

Step 1: Label Namespaces for PSA

# Restricted namespace - production workloads
apiVersion: v1
kind: Namespace
metadata:
  name: production
  labels:
    pod-security.kubernetes.io/enforce: restricted
    pod-security.kubernetes.io/enforce-version: latest
    pod-security.kubernetes.io/audit: restricted
    pod-security.kubernetes.io/audit-version: latest
    pod-security.kubernetes.io/warn: restricted
    pod-security.kubernetes.io/warn-version: latest
# Baseline namespace - general workloads
apiVersion: v1
kind: Namespace
metadata:
  name: staging
  labels:
    pod-security.kubernetes.io/enforce: baseline
    pod-security.kubernetes.io/enforce-version: latest
    pod-security.kubernetes.io/audit: restricted
    pod-security.kubernetes.io/audit-version: latest
    pod-security.kubernetes.io/warn: restricted
    pod-security.kubernetes.io/warn-version: latest
# Privileged namespace - system components only
apiVersion: v1
kind: Namespace
metadata:
  name: kube-system
  labels:
    pod-security.kubernetes.io/enforce: privileged
    pod-security.kubernetes.io/enforce-version: latest

Step 2: Apply Labels to Existing Namespaces

# Apply restricted enforcement to production
kubectl label namespace production \
  pod-security.kubernetes.io/enforce=restricted \
  pod-security.kubernetes.io/audit=restricted \
  pod-security.kubernetes.io/warn=restricted \
  --overwrite

# Apply baseline to staging with restricted warnings
kubectl label namespace staging \
  pod-security.kubernetes.io/enforce=baseline \
  pod-security.kubernetes.io/audit=restricted \
  pod-security.kubernetes.io/warn=restricted \
  --overwrite

# Check labels on all namespaces
kubectl get namespaces -L pod-security.kubernetes.io/enforce

Step 3: Create Compliant Pod Specs

# Restricted-compliant deployment
apiVersion: apps/v1
kind: Deployment
metadata:
  name: secure-app
  namespace: production
spec:
  replicas: 3
  selector:
    matchLabels:
      app: secure-app
  template:
    metadata:
      labels:
        app: secure-app
    spec:
      automountServiceAccountToken: false
      securityContext:
        runAsNonRoot: true
        runAsUser: 65534
        runAsGroup: 65534
        fsGroup: 65534
        seccompProfile:
          type: RuntimeDefault
      containers:
        - name: app
          image: myregistry.com/myapp:v1.0.0@sha256:abc123
          ports:
            - containerPort: 8080
              protocol: TCP
          securityContext:
            allowPrivilegeEscalation: false
            readOnlyRootFilesystem: true
            capabilities:
              drop:
                - ALL
            runAsNonRoot: true
            runAsUser: 65534
          resources:
            requests:
              memory: "64Mi"
              cpu: "100m"
            limits:
              memory: "256Mi"
              cpu: "500m"
          volumeMounts:
            - name: tmp
              mountPath: /tmp
            - name: cache
              mountPath: /var/cache
      volumes:
        - name: tmp
          emptyDir:
            sizeLimit: 100Mi
        - name: cache
          emptyDir:
            sizeLimit: 50Mi

Step 4: Gradual Migration Strategy

# Phase 1: Audit mode - discover violations without blocking
kubectl label namespace my-namespace \
  pod-security.kubernetes.io/audit=restricted \
  pod-security.kubernetes.io/warn=restricted

# Check audit logs for violations
kubectl logs -n kube-system -l component=kube-apiserver | grep "pod-security"

# Phase 2: Enforce baseline, warn on restricted
kubectl label namespace my-namespace \
  pod-security.kubernetes.io/enforce=baseline \
  pod-security.kubernetes.io/warn=restricted \
  --overwrite

# Phase 3: Full restricted enforcement
kubectl label namespace my-namespace \
  pod-security.kubernetes.io/enforce=restricted \
  --overwrite

Step 5: Dry-Run Enforcement Testing

# Test what would happen with restricted enforcement
kubectl label --dry-run=server --overwrite namespace my-namespace \
  pod-security.kubernetes.io/enforce=restricted

# Example output:
# Warning: existing pods in namespace "my-namespace" violate the new
# PodSecurity enforce level "restricted:latest"
# Warning: nginx-xxx: allowPrivilegeEscalation != false,
#   unrestricted capabilities, runAsNonRoot != true, seccompProfile

Baseline Profile Restrictions

Control Restricted Requirement
HostProcess Must not set Pods cannot use Windows HostProcess
Host Namespaces Must not set No hostNetwork, hostPID, hostIPC
Privileged Must not set No privileged: true
Capabilities Baseline list only Only NET_BIND_SERVICE, drop ALL for restricted
HostPath Volumes Must not use No hostPath volume mounts
Host Ports Must not use No hostPort in container spec
AppArmor Default/runtime Cannot set to unconfined
SELinux Limited types Only container_t, container_init_t, container_kvm_t
/proc Mount Type Default only Must use Default proc mount
Seccomp RuntimeDefault or Localhost Must specify seccomp profile (restricted)
Sysctls Safe set only Limited to safe sysctls

Validation Commands

# Verify namespace labels
kubectl get ns --show-labels | grep pod-security

# Test pod creation against policy
kubectl run test-pod --image=nginx --namespace=production --dry-run=server

# Check for violations in audit logs
kubectl get events --field-selector reason=FailedCreate -A

# Scan with Kubescape for PSS compliance
kubescape scan framework nsa --namespace production

References

Other files in this skill

assets/template.md (verbatim)

Pod Security Standards Implementation Template

Namespace Classification

Namespace Current PSS Level Target PSS Level Migration Status
kube-system privileged privileged N/A
production restricted
staging baseline
development baseline

PSS Label Configuration

Namespace enforce audit warn Version
latest

Workload Compliance Checklist

Pod Security Context

  • runAsNonRoot: true
  • runAsUser: non-zero (e.g., 65534)
  • runAsGroup: non-zero
  • fsGroup: appropriate group ID
  • seccompProfile.type: RuntimeDefault

Container Security Context

  • allowPrivilegeEscalation: false
  • readOnlyRootFilesystem: true
  • capabilities.drop: ["ALL"]
  • capabilities.add: only NET_BIND_SERVICE if needed
  • privileged: false (or not set)

Pod Spec

  • automountServiceAccountToken: false (unless needed)
  • No hostNetwork, hostPID, hostIPC
  • No hostPath volumes
  • No hostPort in container specs
  • Resource requests and limits defined

Migration Plan

Phase Action Timeline Status
1 Apply audit+warn labels Week 1
2 Review audit violations Week 2-3
3 Fix workload security contexts Week 4-6
4 Enable baseline enforce Week 7
5 Enable restricted enforce Week 8

Exceptions

Namespace Workload Required Level Justification Approved By

references/api-reference.md (verbatim)

API Reference: Implementing Kubernetes Pod Security Standards

PSA Namespace Labels

# Apply restricted enforcement
kubectl label namespace production \
  pod-security.kubernetes.io/enforce=restricted \
  pod-security.kubernetes.io/audit=restricted \
  pod-security.kubernetes.io/warn=restricted --overwrite

Pod Security Standard Levels

Level Description Blocks
Privileged Unrestricted Nothing
Baseline Minimally restrictive hostNetwork, privileged, hostPID/IPC
Restricted Heavily restricted + runAsNonRoot, drop ALL caps, seccomp

PSA Modes

Mode Behavior
enforce Reject violating pods
audit Log violations (allow pod)
warn Warn user (allow pod)

Baseline Violations

Field Forbidden Value
spec.hostNetwork true
spec.hostPID true
spec.hostIPC true
containers[*].securityContext.privileged true
containers[*].securityContext.capabilities.add Non-default

Restricted Violations (adds to Baseline)

Field Required
runAsNonRoot true
allowPrivilegeEscalation false
capabilities.drop ["ALL"]
seccompProfile.type RuntimeDefault or Localhost

References

references/standards.md (verbatim)

Standards Reference - Kubernetes Pod Security Standards

Kubernetes Pod Security Standards (PSS) v1.31

Privileged Profile

  • No restrictions applied
  • Used for: kube-system, monitoring agents, CNI plugins, storage drivers

Baseline Profile Controls

Control Policy
HostProcess Must be false
Host Namespaces hostNetwork, hostPID, hostIPC must be false
Privileged Containers Must be false
Capabilities Cannot add beyond: AUDIT_WRITE, CHOWN, DAC_OVERRIDE, FOWNER, FSETID, KILL, MKNOD, NET_BIND_SERVICE, SETFCAP, SETGID, SETPCAP, SETUID, SYS_CHROOT
HostPath Volumes Must not be used
Host Ports Must not define hostPort
AppArmor Must not set to unconfined
SELinux type must be container_t, container_init_t, or container_kvm_t; user/role must not be set
/proc Mount Type Must be Default
Seccomp Must not set to Unconfined
Sysctls Must only use safe sysctls

Restricted Profile Controls (in addition to Baseline)

Control Policy
Volume Types Only: configMap, csi, downwardAPI, emptyDir, ephemeral, persistentVolumeClaim, projected, secret
Privilege Escalation allowPrivilegeEscalation must be false
Running as Non-root runAsNonRoot must be true
Running as Non-root User runAsUser must be non-zero
Seccomp Must be RuntimeDefault or Localhost
Capabilities Must drop ALL; may only add NET_BIND_SERVICE

CIS Kubernetes Benchmark v1.8

Section 5: Policies

  • 5.1: RBAC and Service Accounts
  • 5.2: Pod Security Standards
    • 5.2.1: Ensure PSA is not set to Privileged on non-system namespaces
    • 5.2.2: Minimize admission of privileged containers
    • 5.2.3: Minimize admission of containers wanting to share host process ID namespace
    • 5.2.4: Minimize admission of containers wanting to share host IPC namespace
    • 5.2.5: Minimize admission of containers wanting to share host network namespace
    • 5.2.6: Minimize admission of containers with allowPrivilegeEscalation
    • 5.2.7: Minimize admission of root containers
    • 5.2.8: Minimize admission of containers with NET_RAW capability
    • 5.2.9: Minimize admission of containers with added capabilities
    • 5.2.10: Minimize admission of containers with capabilities assigned
    • 5.2.11: Minimize admission of containers with HostProcess
    • 5.2.12: Minimize admission of HostPath volumes
    • 5.2.13: Minimize admission of containers with unrestricted Seccomp profile

NSA/CISA Kubernetes Hardening Guide

Pod Security Recommendations

  • Use PSA in enforce mode for production namespaces
  • Set restricted profile as default for all non-system namespaces
  • Require seccomp profiles on all pods
  • Prevent privileged containers in all workload namespaces
  • Require non-root user for all containers
  • Drop all capabilities and only add NET_BIND_SERVICE if needed

MITRE ATT&CK for Containers

Techniques Prevented by Restricted Profile

Technique PSS Control
T1611 - Escape to Host Blocks privileged, hostPID, hostNetwork
T1610 - Deploy Container Blocks privileged containers
T1053 - Scheduled Task Blocks host namespace access
T1548 - Abuse Elevation Control Blocks allowPrivilegeEscalation

references/workflows.md (verbatim)

Workflows - Kubernetes Pod Security Standards

Workflow 1: PSS Migration from PodSecurityPolicy

[Identify PSP usage] --> [Map PSP to PSS levels] --> [Apply audit/warn labels]
        |                        |                           |
        v                        v                           v
  kubectl get psp          Privileged PSP -> baseline    Monitor audit logs
  List all namespaces      Restrictive PSP -> restricted  for 2-4 weeks
        |                        |                           |
        +------------------------+---------------------------+
                                 |
                                 v
                    [Enable enforce mode per namespace]
                                 |
                                 v
                    [Remove PodSecurityPolicy resources]
                                 |
                                 v
                    [Disable PSP admission controller]

Workflow 2: New Namespace Onboarding

Step 1: Classify workload sensitivity
  - System/Infrastructure -> Privileged (only kube-system)
  - General workloads -> Baseline + Restricted warnings
  - Production/Sensitive -> Restricted enforce

Step 2: Create namespace with labels
  kubectl create namespace $NS
  kubectl label namespace $NS \
    pod-security.kubernetes.io/enforce=$LEVEL \
    pod-security.kubernetes.io/audit=restricted \
    pod-security.kubernetes.io/warn=restricted

Step 3: Test with dry-run
  kubectl run test --image=nginx -n $NS --dry-run=server

Step 4: Deploy workloads with compliant security contexts

Step 5: Validate enforcement
  kubectl get events -n $NS --field-selector reason=FailedCreate

Workflow 3: CI/CD PSS Compliance Check

# Pre-deployment validation
name: PSS Compliance Check
on: pull_request

jobs:
  validate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Install kubescape
        run: curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash

      - name: Scan manifests for PSS restricted compliance
        run: |
          kubescape scan framework nsa \
            --controls-config controls.json \
            --format junit --output results.xml \
            k8s-manifests/

      - name: Validate security contexts
        run: |
          for file in k8s-manifests/*.yaml; do
            echo "Checking $file..."
            # Verify runAsNonRoot
            if ! grep -q "runAsNonRoot: true" "$file"; then
              echo "FAIL: Missing runAsNonRoot in $file"
              exit 1
            fi
            # Verify drop ALL
            if ! grep -q "drop:" "$file" || ! grep -A1 "drop:" "$file" | grep -q "ALL"; then
              echo "FAIL: Missing drop ALL capabilities in $file"
              exit 1
            fi
          done

Workflow 4: Violation Response

[PSA Violation Detected]
        |
        +-- enforce mode --> Pod rejected --> Alert developer
        |                                         |
        |                                         v
        |                                   Fix security context
        |                                   Re-deploy
        |
        +-- audit mode --> Pod allowed, audit log entry
        |                         |
        |                         v
        |                   Weekly audit review
        |                   Create remediation ticket
        |
        +-- warn mode --> Pod allowed, user warning
                                |
                                v
                          Developer sees warning
                          Fix before enforce rollout

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.