PodSecurityStandards (PSSs) have replaced PodSecurityPolicies (PSPs) as Kubernetes' builtin security control.
That said, they're quite different. Here are the top 6 things to know about Pod Security Standards.
1. Pod Security Standards are opinionated
Pod Security Policies (now deprecated) were a tool for creating policies. But the content of those policies was up to you. With Pod Security Standards, there is no more creating policies! You get three predefined security levels out of the box.
2. Pod Security Standards apply to namespaces
Pod Security Standards are applied to namespaces. When applied, they impose requirements on all Pods in the namespace.
3. To set a Pod Security Standard, you label the namespace
Interesting design decision here. Namespaces don't have a new YAML field specifying their Security Standard. Instead, you just add a special label to the namespace.
4. Pod Security Standards can be enforced, warning-only, or audit-only
Security Standards are checked at runtime via admission control. There are three possible modes: Enforcement, Warning, and Audit.
