Skip to Content
Hands-On Microservices with Kubernetes
book

Hands-On Microservices with Kubernetes

by Gigi Sayfan
July 2019
Intermediate to advanced
502 pages
14h
English
Packt Publishing
Content preview from Hands-On Microservices with Kubernetes

Hardening your pods with security policies

A pod security policy allows you set a global policy that applies to all newly created pods. It is enforced as part of the admission stage of access control. The pod security policy can create a security context for pods with no security context or reject pod creation and updating if they have a security context that doesn't match the policy. Here is a security policy that will prevent pods from getting a privileged status that allows access to host devices:

apiVersion: policy/v1beta1kind: PodSecurityPolicymetadata:  name: disallow-privileged-accessspec:  privileged: false  allowPrivilegeEscalation: false  # required fields.  seLinux:    rule: RunAsAny  supplementalGroups:    rule: RunAsAny  runAsUser: rule: ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Kubernetes Microservices

Kubernetes Microservices

Richard Chesterwood
Cloud Native DevOps with Kubernetes

Cloud Native DevOps with Kubernetes

John Arundel, Justin Domingus
Microservices: Up and Running

Microservices: Up and Running

Ronnie Mitra, Irakli Nadareishvili

Publisher Resources

ISBN: 9781789805468Supplemental Content