Hedronite · Cert Lesson · Cert-Prep / CNCF · Sat 2026-09-12

CKS Pod Security Admission — restricted enforce and FailedCreate proof

On the exam, enforce is a label. Proof is a FailedCreate after you delete a privileged Pod.

Lesson Class: Cert-Prep (CKS · Pod Security Admission)
Paired Ops: AKS Pod Security Admission
Paired Dev: Python PSA label census
Paired Go: client-go PSA namespace informer
Grounding: CKS Q14 · Q47 · kubestronaut CKS §4
Label
enforce=restricted.
Fix
Harden the pod template.
Prove
Capture FailedCreate.
Label first, prove with FailedCreate, then harden the template so recreate succeeds.

On the exam, enforce is a label. Proof is a FailedCreate after you delete a privileged Pod.

§I — Frame

CKS Minimize Microservice Vulnerabilities items often center on Pod Security Admission. Bootcamp Q14 gives a namespace already at enforce=restricted and a broken Deployment YAML. Q47 gives a privileged Deployment already running and asks you to label the namespace, delete a Pod, and capture FailedCreate events. PSA replaced PodSecurityPolicy (removed in Kubernetes 1.25).

§II — Objective map

NeedMechanism
Reject bad pods in a namespacekubectl label ns NAME pod-security.kubernetes.io/enforce=restricted
Stage without rejectaudit=restricted and/or warn=restricted
Fix a templateRemove privileged/root/hostPath; set runAsNonRoot, allowPrivilegeEscalation false, capabilities.drop ALL, readOnlyRootFilesystem, seccomp RuntimeDefault
Prove enforce on live workloadDelete a Pod; ReplicaSet recreate hits admission; capture FailedCreate

§III — Q14 drill pattern

  1. Read the insecure manifest: privileged, runAsUser 0, NET_ADMIN, hostPath.
  2. Edit toward restricted: drop ALL caps, non-root UID, emptyDir, allowPrivilegeEscalation false, readOnlyRootFilesystem true, seccompProfile type RuntimeDefault.
  3. kubectl apply -f ... into the labeled namespace.
  4. Confirm Deployment ready.

§IV — Q47 drill pattern

  1. Label team-blue with enforce=restricted.
  2. Confirm labels: kubectl get ns team-blue --show-labels.
  3. Delete one Pod from the privileged Deployment.
  4. Watch ReplicaSet: recreate fails.
  5. Capture events: kubectl get events -n team-blue --field-selector reason=FailedCreate (or kubectl describe rs ...) into the required path.

Remember: existing Pods are not ejected by the label alone. Deletion (or a new create) is what triggers the check.

§V — Exam discriminators

§VI — Study drill

From memory, write the three label keys and the minimal SecurityContext for restricted. Timebox to 6 minutes. Then run Q14 once without notes.

§VII — Closing

Label first, prove with FailedCreate, then harden the template so recreate succeeds.

Related