Hands-on Lab·Certified Kubernetes Security Specialist
Pod Security Admission: enforce, audit and warn
Every namespace you create admits a privileged container and says nothing about it. This guide turns that off in the order a real rollout needs - find out what breaks, record it, then refuse it - and shows the one thing labelling a namespace will never do.
Microservice Vulnerabilities Guide 18 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 17 min
- Reviewed25 August 2026
Written against the versions above. Pod Security Admission is built into the apiserver and is configured entirely with namespace labels. There is no controller to install and nothing to keep running.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 4 - the other namespace-level control.
-
A namespace with no level set
-
Warn and audit before you enforce
-
Enforce, and read the refusal
-
The level below, and what it does not cover