Kubernetes
Practical
By Samson Tanimawo, PhD
Published Jan 14, 2026
4 min read
Pod Security Admission
PSA replaces PSP. The migration.
Live workflow · 3 working · 1 queuedLive
Signal · gather Working
Decide · pick action Working
Apply · with verify Working
Learn · update playbook Queued
Modes
enforce, audit, warn per namespace.
Test with audit; switch to enforce.
Levels
privileged, baseline, restricted.
Baseline default; restricted for hardened.
Migrate
Per namespace; prod last.
Catches the egregious before it ships.