Slide 49
Slide 49 text
CONFIDENTIAL Designator
PSa enforcement (Tech Preview)
"configuration": {
"apiVersion":
"pod-security.admission.config.k8s.io/v1bet
a1",
"defaults": {
"audit": "restricted",
"audit-version": "latest",
"enforce": "restricted",
"enforce-version": "latest",
"warn": "restricted",
"warn-version": "latest"
},
"exemptions": {
"usernames": [
"system:serviceaccount:openshift-infra:buil
d-controller"
]
},
"kind": "PodSecurityConfiguration"
}
}
oc patch featuregate cluster -p '{"spec":
{"featureSet":
"TechPreviewNoUpgrade"}}' --type
merge
{
"configuration": {
"apiVersion":
"pod-security.admission.config.k8s.io/v1bet
a1",
"defaults": {
"audit": "restricted",
"audit-version": "latest",
"enforce": "privileged",
"enforce-version": "latest",
"warn": "restricted",
"warn-version": "latest"
},
"exemptions": {
"usernames": [
"system:serviceaccount:openshift-infra:buil
d-controller"
]
},
"kind": "PodSecurityConfiguration"
}
}
PSa Default config 4.13 PSa enforced config
Test PSa
enforcement for
workloads with
FeatureGate