DevOps Daily with Fexingo · 2026-08-05 · 9 min
In this episode of DevOps Daily with Fexingo, hosts Lucas and Luna uncover a quiet but dangerous gap in Kubernetes security: running Pod Security Admission in audit mode can let risky workloads slip into production without a single warning. They trace a real scenario where a team thought they were protected by PSA audit logs, but misconfigured exclusions and permissive policies meant no alert ever fired. Drawing on the Kubernetes 1.23 introduction of Pod Security Standards, Lucas explains how audit mode differs from enforce mode, why relying on logs alone creates blind spots, and how a simple validation check - like a pre-deployment policy scan - can save your cluster from a nasty surprise. Perfect for platform engineers and SREs who think they've got Pod Security covered. Tune in to learn one concrete takeaway: audit mode is a starting point, not a safety net. #Kubernetes #PodSecurityAdmission #PodSecurityStandards #AuditMode #DevOps #KubernetesSecurity #PodSecurity #PlatformEngineering #CloudNative #KubernetesTips #SecurityBestPractices #SRE #CI/CD #TechPodcast #FexingoBusiness #BusinessPodcast #DevOpsDaily #KubernetesAdmission Keep every episode free: buymeacoffee.com/fexingo