Pod Security Standards are the default answer for “make workloads run non-privileged” in Kubernetes.
They replace the removed PodSecurityPolicy admission controller with three policies, Baseline, Restricted, and Privileged, that can be enforced or audited per namespace. The model is simple, but production mistakes come from exemptions, admission confusion, and treating the label as the control.
This note covers operating Pod Security Standards on real clusters.
Know The Three Policies Privileged: unrestricted, for system workloads that legitimately need it. Baseline: allows the default Kubernetes behavior while preventing known privilege escalation. Good starting point for most non-system namespaces. Restricted: the hardened target. No privileged containers, no host network, strict volume and capability limits. Baseline is the pragmatic default. Restricted is the goal where the workload can satisfy it. Privileged is a documented exception, not a default.
...