Description
Without policies that enforce the required restrictions, Pods can use privileged execution, excessive capabilities or host access. PodSecurityPolicy was deprecated in Kubernetes v1.21 and removed in v1.25. Modern clusters need the required restrictions through Pod Security Admission or a policy engine.
Potential impact
- Pods with excessive privileges can be deployed more easily.
- Host access and privilege escalation can be harder to control.
- Workload security standards can vary between teams.
Remediation
- Configure Pod Security Admission in enforce mode or a supported policy engine on current clusters, allowing only necessary exceptions. Audit and warn modes do not block requests.
- Review policies and their use permissions in legacy PSP environments and migrate to supported controls. Enabling the feature alone does not enforce the required restrictions; test allowed and denied cases.
Examples
These excerpts are for older GKE and provider versions that supported PSP. Do not add this block to current clusters; use supported policy features.
Before
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
pod_security_policy_config {
enabled = false
}
timeouts {
create = "30m"
update = "40m"
}
}
After
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
pod_security_policy_config {
enabled = true
}
timeouts {
create = "30m"
update = "40m"
}
}
Explanation:
- Before: The legacy PSP feature is disabled. Check other policy controls separately.
- After: The legacy PSP feature is enabled. Enforcement also requires PSP policies and the RBAC permissions to use them.