docs/doc/source/security/kubernetes/enable-pod-security-policy-checking.rst
Rafael Jardim d95c80d36f Update Security
Fixed merge conflict (RS)

Signed-off-by: Rafael Jardim <rafaeljordao.jardim@windriver.com>
Change-Id: I30b882a14196525f440db1108a56bbf862dfaf55
Signed-off-by: Ron Stone <ronald.stone@windriver.com>
2021-04-01 16:02:36 -04:00

789 B

Enable Pod Security Policy Checking

  1. Set the kubernetes kube_apiserver admission_plugins system parameter to include PodSecurityPolicy.

    ~(keystone_admin)]$ system service-parameter-add kubernetes kube_apiserver admission_plugins=PodSecurityPolicy
  2. Apply the Kubernetes system parameters.

    ~(keystone_admin)]$ system service-parameter-apply kubernetes
  3. View the automatically added pod security policies.

    $ kubectl get psp
    $ kubectl describe <psp> privileged
    $ kubectl describe <psp> restricted