Reference meta
podSecurity
Declare the Pod Security Admission level a package needs from its namespace.
Set meta.podSecurity when a package’s pods need a particular Kubernetes Pod
Security Standards level:
meta = { version = "1.0.0"; podSecurity = "privileged";};The value is one of privileged, baseline, or restricted, ordered from
most to least permissive. Kix evaluates the declarations of every instance in
a namespace and writes the most permissive requested level to the Namespace:
pod-security.kubernetes.io/enforce: privilegedWhen no instance declares a level and the cluster does not configure one, Kix writes no Pod Security Admission label.
The cluster can set namespaces.<name>.podSecurity directly. Kix rejects a
value that is stricter than any package in the namespace requests because
Kubernetes would refuse that package’s pods. When package declarations exist,
their most permissive level is the one rendered; a more permissive namespace
setting does not raise it further.
meta.podSecurity controls the namespace admission label. It does not exempt
a package from scorecard rules or from cluster capability checks. Use
meta.unsafe only for one of its specific,
audited exceptions.