GnoseedGnoseed
Security · Flashcard

Which requirement does the restricted Pod Security Standard add on top of baseline?

Why this is the answer

Restricted layers pod-hardening requirements on top of baseline: runAsNonRoot, allowPrivilegeEscalation set to false, a seccompProfile of RuntimeDefault or Localhost, capabilities dropped to ALL, and a narrow volume-type allowlist. Blocking hostPath and host networking is already baseline, and so is refusing privileged containers and dangerous capabilities such as CAP_SYS_ADMIN. Resource limits belong to neither standard — they are a quota concern, enforced by LimitRange or a policy engine.

Read more in the docs
Study in Gnoseed →