DevOps Daily with Fexingo · 2026-08-28 · 10 min
In episode 169 of DevOps Daily, Lucas and Luna dive into Kubernetes Pod Security Admission (PSA) and the three built-in policies: privileged, baseline, and restricted. They walk through a real incident where a seemingly innocent deployment broke after PSA was enabled, examine how exemptions can silently weaken the guardrails, and discuss why moving to restricted is harder than it looks. With PSA now defaults in managed clusters like EKS and GKE, understanding pod security standards is essential for any platform engineer. Lucas explains how to audit existing workloads with the warning mode before enforcing, while Luna brings a cautionary tale about a cluster where PSA lulled everyone into a false sense of security. Tune in for a practical breakdown of a feature that can save your cluster from running containers with root privileges or hostPath mounts. #Kubernetes #PodSecurityAdmission #PSA #PodSecurityStandards #DevOps #CloudNative #Security #Workloads #EKS #GKE #ContainerSecurity #AdmissionControl #PrivilegedContainers #RestrictedPolicy #BaselinePolicy #ClusterSecurity #FexingoBusiness #BusinessPodcast Keep every episode free: buymeacoffee.com/fexingo