Description
In a legacy cluster that relies on PodSecurityPolicy, creating PSP resources does not enforce their restrictions while the admission plugin is disabled. Check permission to use the policies and whether they govern actual Pod creation requests.
PSP was deprecated in Kubernetes 1.21 and removed in 1.25. Use supported controls such as Pod Security Admission on current clusters instead of adding PSP.
Potential impact
- Without the intended enforcement, privileged execution or host access may be allowed beyond the required scope.
- Enabling the plugin before preparing policies and permission to use them can also reject necessary Pod creation.
Remediation
- In legacy environments, prepare the required PSPs and minimal
usepermissions before enabling the plugin. - Move the required restrictions to current admission controls while migrating to supported Kubernetes.
- Test that approved workloads deploy and prohibited settings are rejected.
Examples
These are API server configuration excerpts for the unsupported Kubernetes 1.24.17 release, not a recommended version for new installations. The remaining control-plane configuration, including certificates and storage, is required separately.
Before
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.24.17
command:
- "kube-apiserver"
args:
- "--disable-admission-plugins=PodSecurityPolicy"
The PSP plugin is explicitly disabled. Assess protection supplied by other admission controls separately.
After
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.24.17
command:
- "kube-apiserver"
args:
- "--enable-admission-plugins=PodSecurityPolicy"
The PSP plugin is enabled. The applicable policies and permission to use them must already be prepared.