Skip to content
kix /docs
Install the CLI

Reference meta

podSecurity

Declare the Pod Security Admission level a package needs from its namespace.

Set meta.podSecurity when a package’s pods need a particular Kubernetes Pod Security Standards level:

meta = {
version = "1.0.0";
podSecurity = "privileged";
};

The value is one of privileged, baseline, or restricted, ordered from most to least permissive. Kix evaluates the declarations of every instance in a namespace and writes the most permissive requested level to the Namespace:

pod-security.kubernetes.io/enforce: privileged

When no instance declares a level and the cluster does not configure one, Kix writes no Pod Security Admission label.

The cluster can set namespaces.<name>.podSecurity directly. Kix rejects a value that is stricter than any package in the namespace requests because Kubernetes would refuse that package’s pods. When package declarations exist, their most permissive level is the one rendered; a more permissive namespace setting does not raise it further.

meta.podSecurity controls the namespace admission label. It does not exempt a package from scorecard rules or from cluster capability checks. Use meta.unsafe only for one of its specific, audited exceptions.