Enable Pod Security Policy CheckingΒΆ

Procedure

  1. Set the kubernetes kube_apiserver admission_plugins system parameter to include PodSecurityPolicy.

    ~(keystone_admin)]$ system service-parameter-add kubernetes kube_apiserver admission_plugins=PodSecurityPolicy
    
  2. Apply the Kubernetes system parameters.

    ~(keystone_admin)]$ system service-parameter-apply kubernetes
    
  3. View the automatically added pod security policies.

    $ kubectl get psp
    $ kubectl describe <psp> privileged
    $ kubectl describe <psp> restricted