Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy
A security architect is designing a multi-tenant Kubernetes cluster. To ensure strong isolation and prevent privilege escalation, they want to prevent Pods from running as root, using host namespaces, or accessing sensitive host paths. Which Kubernetes admission controller is specifically designed to enforce these types of Pod-level security best practices?
- ALimitRange
- BResourceQuota
- CNodeRestriction
- DPod Security Admission (PSA)
Show answer & explanationAnswer & explanation
Correct answer: D. Pod Security Admission (PSA)
Pod Security Admission (PSA) is a built-in Kubernetes admission controller that enforces Pod Security Standards (PSS). PSS defines three levels (Privileged, Baseline, Restricted) that directly address the requirements like preventing root execution, host namespace usage, and host path access, ensuring strong Pod-level security.
Why the other options are wrong
- A. LimitRange sets default resource limits and requests for Pods, but does not enforce security contexts.
- B. ResourceQuota limits resource consumption (CPU, memory) within a namespace, not Pod security contexts.
- C. NodeRestriction limits the API objects that kubelets can modify, primarily for node security, not for enforcing Pod-level security contexts during creation.
Pod Security Admission (PSA)
A built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) on Pods, ensuring they adhere to predefined security policies.
- Enforces 'Privileged', 'Baseline', and 'Restricted' security standards.
- Can be configured at the namespace level to 'enforce', 'audit', or 'warn'.
- Directly addresses common Pod security misconfigurations.
Memory trick: PSA: Pod Security Admission enforces standards.