/implementing-pod-security-admission-controller
Implement Kubernetes Pod Security Admission (PSA) with controlled policy rollout (`audit`,.
Implement Kubernetes Pod Security Admission (PSA) with controlled policy rollout (`audit`, `warn`, `enforce`) to raise workload security posture without destabilizing operations.
Category
Security
Execution
7 steps, sequential + gated
Goal
Implement Kubernetes Pod Security Admission (PSA) with controlled policy rollout (`audit`, `warn`, `enforce`) to raise workload security posture without destabilizing operations.
Scope
Applies to
- +Enable Pod Security Admission
- +Migrate from PodSecurityPolicy to PSA
- +Enforce baseline/restricted policies per namespace
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Enable Pod Security Admission""Migrate from PodSecurityPolicy to PSA""Enforce baseline/restricted policies per namespace""Audit pod security violations before enforcement"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Production namespaces should not jump directly to strict enforcement without audit evidence.
- 02Enforcement versions must be pinned for deterministic behavior across upgrades.
- 03Exemptions must be minimal, explicit, and justified.
- 04Any breaking enforcement change requires rollback readiness before rollout.
Procedure
- Step 1Step 1 — **Assess current workload posture**
- Step 2Step 2 — **Define target policy map**
- Step 3Step 3 — **Start with audit and warn**
- Step 4Step 4 — **Remediate violating workloads**
- Step 5Step 5 — **Enable enforcement progressively**
- Step 6Step 6 — **Configure cluster defaults (optional)**
- Step 7Step 7 — **Verify and stabilize**
Outputs
- ▸Namespace PSA label plan and applied label evidence.
- ▸Violation/remediation report from audit and warn phases.
- ▸Enforcement rollout report with accepted/rejected workload outcomes.
- ▸Exemption register with owner, reason, and review date.
Review Gate
- [ ]Target policy profile per namespace is explicit and version-pinned.
- [ ]Audit/warn evidence exists before strict enforcement in sensitive namespaces.
- [ ]Violating workloads are remediated or formally excepted.
- [ ]Enforcement rollout is staged and operationally validated.
- [ ]Exemptions are justified, minimal, and tracked.