CKS Pod Security Admission — restricted enforce and FailedCreate proof
On the exam, enforce is a label. Proof is a FailedCreate after you delete a privileged Pod.
On the exam, enforce is a label. Proof is a FailedCreate after you delete a privileged Pod.
§I — Frame
CKS Minimize Microservice Vulnerabilities items often center on Pod Security Admission. Bootcamp Q14 gives a namespace already at enforce=restricted and a broken Deployment YAML. Q47 gives a privileged Deployment already running and asks you to label the namespace, delete a Pod, and capture FailedCreate events. PSA replaced PodSecurityPolicy (removed in Kubernetes 1.25).
§II — Objective map
| Need | Mechanism |
|---|---|
| Reject bad pods in a namespace | kubectl label ns NAME pod-security.kubernetes.io/enforce=restricted |
| Stage without reject | audit=restricted and/or warn=restricted |
| Fix a template | Remove privileged/root/hostPath; set runAsNonRoot, allowPrivilegeEscalation false, capabilities.drop ALL, readOnlyRootFilesystem, seccomp RuntimeDefault |
| Prove enforce on live workload | Delete a Pod; ReplicaSet recreate hits admission; capture FailedCreate |
§III — Q14 drill pattern
- Read the insecure manifest: privileged, runAsUser 0, NET_ADMIN, hostPath.
- Edit toward restricted: drop ALL caps, non-root UID, emptyDir, allowPrivilegeEscalation false, readOnlyRootFilesystem true, seccompProfile type RuntimeDefault.
kubectl apply -f ...into the labeled namespace.- Confirm Deployment ready.
§IV — Q47 drill pattern
- Label
team-bluewith enforce=restricted. - Confirm labels:
kubectl get ns team-blue --show-labels. - Delete one Pod from the privileged Deployment.
- Watch ReplicaSet: recreate fails.
- Capture events:
kubectl get events -n team-blue --field-selector reason=FailedCreate(orkubectl describe rs ...) into the required path.
Remember: existing Pods are not ejected by the label alone. Deletion (or a new create) is what triggers the check.
§V — Exam discriminators
- Profile names are lowercase:
restricted,baseline,privileged. - Mode names are
enforce,audit,warn(not "deny"). - Wrong key typos fail silently as "no PSA label."
- NetworkPolicy answers do not satisfy a PSA stem.
§VI — Study drill
From memory, write the three label keys and the minimal SecurityContext for restricted. Timebox to 6 minutes. Then run Q14 once without notes.
§VII — Closing
Label first, prove with FailedCreate, then harden the template so recreate succeeds.
Related
- Ops
- Dev
- Go