-
Notifications
You must be signed in to change notification settings - Fork 429
Open
Labels
enhancementNew feature or requestNew feature or requestneeds-designquestionFurther information is requestedFurther information is requested
Milestone
Description
Is your feature request related to a problem? Please describe.
Pod security polices are deprecated since 1.21. However, k0s still allows configuring a default PodSecurityPolicy and the security model seems to depend on it
Describe the solution you would like
I've been searching on the repo for any discussion about this and couldn't find anything, so this issue is just to know what will happen next.
PodSecurity is confirmed to be the native successor and is already in beta and enabled by default in the latest k0s
There are other options too like Open Policy Agent (OPA). They may be more sophisticated but would bring in a new dependency to manage
Describe alternatives you've considered
There is no other alternative, since PSP are already deprecated
Additional context
No response
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestneeds-designquestionFurther information is requestedFurther information is requested