Don't recommend PSP usage, since it's deprecated
This commit is contained in:
parent
ae1ae50454
commit
8b5fb9939b
|
@ -49,13 +49,12 @@ administrator to control the following:
|
||||||
|
|
||||||
## Enabling Pod Security Policies
|
## Enabling Pod Security Policies
|
||||||
|
|
||||||
Pod security policy control is implemented as an optional (but recommended)
|
Pod security policy control is implemented as an optional [admission
|
||||||
[admission
|
controller](/docs/reference/access-authn-authz/admission-controllers/#podsecuritypolicy).
|
||||||
controller](/docs/reference/access-authn-authz/admission-controllers/#podsecuritypolicy). PodSecurityPolicies
|
PodSecurityPolicies are enforced by [enabling the admission
|
||||||
are enforced by [enabling the admission
|
|
||||||
controller](/docs/reference/access-authn-authz/admission-controllers/#how-do-i-turn-on-an-admission-control-plug-in),
|
controller](/docs/reference/access-authn-authz/admission-controllers/#how-do-i-turn-on-an-admission-control-plug-in),
|
||||||
but doing so without authorizing any policies **will prevent any pods from being
|
but doing so without authorizing any policies **will prevent any pods from being created** in the
|
||||||
created** in the cluster.
|
cluster.
|
||||||
|
|
||||||
Since the pod security policy API (`policy/v1beta1/podsecuritypolicy`) is
|
Since the pod security policy API (`policy/v1beta1/podsecuritypolicy`) is
|
||||||
enabled independently of the admission controller, for existing clusters it is
|
enabled independently of the admission controller, for existing clusters it is
|
||||||
|
@ -707,5 +706,3 @@ Refer to the [Sysctl documentation](
|
||||||
- See [Pod Security Standards](/docs/concepts/security/pod-security-standards/) for policy recommendations.
|
- See [Pod Security Standards](/docs/concepts/security/pod-security-standards/) for policy recommendations.
|
||||||
|
|
||||||
- Refer to [Pod Security Policy Reference](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#podsecuritypolicy-v1beta1-policy) for the api details.
|
- Refer to [Pod Security Policy Reference](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#podsecuritypolicy-v1beta1-policy) for the api details.
|
||||||
|
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue