Security Admission Control - Motivatio n + https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/2579-psp-replacement#motivation + PodSecurityPolicy Deprecation: Past, Present, and Futur e + https://kubernetes.io/blog/2021/04/06/podsecuritypolicy-deprecation-past-present-and-future/#why-is-podsecuritypolicy-going-away It is easy to accidentally grant broader permissions than intended, and dif fi cult to inspect which PSP(s) apply in a given situation. The “changing Pod defaults” feature can be handy, but is only supported for certain Pod settings and it’s not obvious when they will or will not apply to your Pod . Without a “dry run” or audit mode, it’s impractical to retro fi t PSP to existing clusters safely, and it’s impossible for PSP to ever be enabled by default. [PodSecurityPolicy Deprecation: Past, Present, and FutureΑΓҾ༻]
seccompʹݶͬͯݴ͑σϑΥϧτΛೖ͢Δઐ༻ͷػೳ͕͋Δ + v1.22͔Βalphaͱͯ͠ఏڙ͞ΕFeature GateͰ༗ޮԽ͢Δͱར༻Մೳ + Enable seccomp for all workloads with a new v1.22 alpha featur e + https://kubernetes.io/blog/2021/08/25/seccomp-default/
ಛఆͷhostPath͚ͩڐՄ Έ͍ͨͳ͜ͱͰ͖ͳ͍ ▶ ಠࣗͷϙϦγʔWebhookͰ࣮͠ͳ͚ΕͳΒͳ͍͔ʁ + KEP-2579: Pod Security Admission ControlͷCustom Pro fi le s + https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/2579-psp-replacement#custom-pro fi les + ͔͠͠betaͰCustom Pro fi lesແ͘ͳΓͦ͏ … + https://github.com/kubernetes/enhancements/pull/2895ɹ(2021/8/25࣌Ͱ·ͩmerge͞Ε͍ͯͳ͍ ) + ͦ͏ͳΔͱStandaloneͷPodSecurityΛFork࣮ͯ͢͠Δ͔͠ͳ͍…?