← docsSecurity

/implementing-pod-security-admission-controller

Implement Kubernetes Pod Security Admission (PSA) with controlled policy rollout (`audit`,.

Implement Kubernetes Pod Security Admission (PSA) with controlled policy rollout (`audit`, `warn`, `enforce`) to raise workload security posture without destabilizing operations.

Category

Security

Execution

7 steps, sequential + gated

Goal

Implement Kubernetes Pod Security Admission (PSA) with controlled policy rollout (`audit`, `warn`, `enforce`) to raise workload security posture without destabilizing operations.

Scope

Applies to

  • +Enable Pod Security Admission
  • +Migrate from PodSecurityPolicy to PSA
  • +Enforce baseline/restricted policies per namespace

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Enable Pod Security Admission""Migrate from PodSecurityPolicy to PSA""Enforce baseline/restricted policies per namespace""Audit pod security violations before enforcement"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Production namespaces should not jump directly to strict enforcement without audit evidence.
  • 02Enforcement versions must be pinned for deterministic behavior across upgrades.
  • 03Exemptions must be minimal, explicit, and justified.
  • 04Any breaking enforcement change requires rollback readiness before rollout.

Procedure

  1. Step 1Step 1 — **Assess current workload posture**
  2. Step 2Step 2 — **Define target policy map**
  3. Step 3Step 3 — **Start with audit and warn**
  4. Step 4Step 4 — **Remediate violating workloads**
  5. Step 5Step 5 — **Enable enforcement progressively**
  6. Step 6Step 6 — **Configure cluster defaults (optional)**
  7. Step 7Step 7 — **Verify and stabilize**

Outputs

  • ▸Namespace PSA label plan and applied label evidence.
  • ▸Violation/remediation report from audit and warn phases.
  • ▸Enforcement rollout report with accepted/rejected workload outcomes.
  • ▸Exemption register with owner, reason, and review date.

Review Gate

  • [ ]Target policy profile per namespace is explicit and version-pinned.
  • [ ]Audit/warn evidence exists before strict enforcement in sensitive namespaces.
  • [ ]Violating workloads are remediated or formally excepted.
  • [ ]Enforcement rollout is staged and operationally validated.
  • [ ]Exemptions are justified, minimal, and tracked.