Pod Security Admission

PSA replaces PSP. The migration.

Modes

Pod Security Admission (PSA) replaced the deprecated PodSecurityPolicy. PSA enforces Pod Security Standards at admission time; pods that violate the standards are rejected. The discipline is configuring PSA correctly: choosing the right mode and level per namespace.

What modes PSA supports:

The modes provide flexibility. The team chooses what fits the namespace's stage of adoption.

Levels

The Pod Security Standards levels (privileged, baseline, restricted) determine what is enforced. Each level has progressively stricter requirements; the choice matches the namespace's role.

Levels match the security requirement. Higher levels for higher stakes; the choice is per-namespace.

Migrate

The migration to PSA is incremental. Per-namespace rollout; production last; catch the egregious patterns before they reach production.

Pod Security Admission is one of those Kubernetes security disciplines that pays off across many namespaces. Nova AI Ops integrates with cluster admission data, surfaces PSA violations and configurations, and produces the per-namespace visibility that the security team uses to drive harder defaults over time.