Back to blog

Mar 30, 2023

PodSecurityStandards vs. PodSecurityPolicies

PodSecurityStandards (PSSs) have replaced PodSecurityPolicies (PSPs) as Kubernetes' builtin security control.

PodSecurityStandards vs. PodSecurityPolicies

PodSecurityStandards (PSSs) have replaced PodSecurityPolicies (PSPs) as Kubernetes' builtin security control.

That said, they're quite different. Here are the top 6 things to know about Pod Security Standards.

1. Pod Security Standards are opinionated

Pod Security Policies (now deprecated) were a tool for creating policies. But the content of those policies was up to you. With Pod Security Standards, there is no more creating policies! You get three predefined security levels out of the box.

2. Pod Security Standards apply to namespaces

Pod Security Standards are applied to namespaces. When applied, they impose requirements on all Pods in the namespace.

3. To set a Pod Security Standard, you label the namespace

Interesting design decision here. Namespaces don't have a new YAML field specifying their Security Standard. Instead, you just add a special label to the namespace.

4. Pod Security Standards can be enforced, warning-only, or audit-only

Security Standards are checked at runtime via admission control. There are three possible modes: Enforcement, Warning, and Audit.

See it running in your environment.

We'll help you get Robusta installed on your cluster and walk through a live incident.

Prefer to tell us about your setup first?