About pod security admission
You can use pod security admission modes, such as enforce, warn, or audit, along with security profiles to restrict which pods run in your cluster. You can apply this control at both the global and namespace levels.
Globally, the privileged profile is enforced, and the restricted profile is used for warnings and audits.
You can also configure the pod security admission settings at the namespace level.
|
|
Do not run workloads in or share access to default projects. Default projects are reserved for running core cluster components. The following default projects are considered highly privileged: |