Hands-on Lab·Kubernetes and Cloud Native Security Associate
Pod Security Standards in Detail
`privileged`, `baseline` and `restricted` are easy to recite and hard to place. This guide builds the matrix: an ordinary Pod and a privileged one, submitted to all three levels, plus the host-namespace case that shows what baseline is for.
Security Fundamentals Guide 22 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. Pod Security Admission is built into the apiserver, so none of this needs anything installed. The warning text names the version it evaluated against - `restricted:latest` here - which is why pinning `enforce-version` matters.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
Three namespaces, one per level
-
A privileged Pod: only one level takes it
-
An ordinary Pod: the line between baseline and restricted
-
Host namespaces, and what they actually expose
-
warn mode, which is how a rollout actually happens