The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/DevOps Daily with Fexingo
DevOps Daily with Fexingo artwork

How Kubernetes Pod Security Standards Block Supply Chain Attacks

DevOps Daily with Fexingo · 2026-07-22 · 10 min

0:00--:--

Topics in this episode

kubernetes pod security standardspod security admissionk8s supply chain attackcontainer image compromiseprivilege escalation kubernetes

Episode notes

In DevOps Daily Episode 127, Lucas and Luna explore how Kubernetes Pod Security Standards (PSS) can block common supply chain attack vectors. They dissect a real-world scenario where a compromised container image from a public registry tries to escalate privileges via hostPath mounts. Lucas explains the three PSS levels - Privileged, Baseline, and Restricted - and how migrating from the deprecated PodSecurityPolicy to PSS with admission controllers like Kyverno or OPA Gatekeeper can enforce least-privilege policies. They also discuss the attack path where a malicious sidecar container bypasses classic security scans, and how PSS's 'Restricted' profile catches privilege escalation at admission time. The hosts share migration tips, common pitfalls (like blocking legitimate workloads), and why PSS adoption is accelerating as Kubernetes 1.25+ removes PSP. A must-listen for platform engineers and security-conscious DevOps teams.

More from DevOps Daily with Fexingo

All episodes →
  • How Kubernetes Namespace Quotas Trigger Unexpected Failures58 / 100
  • Why Your Kubernetes Cost Reports Are Lying To You
  • How Kubernetes Node Pools Can Cost You More Than You Think
  • How Kubernetes Pod Overhead Changes Node Capacity Calculations
  • How Kubernetes Pod Security Admission Blocks Risky Workloads
Explore the best B2B Engineering & DevTools podcasts →
All DevOps Daily with Fexingo episodes →