A cluster is running Kubernetes 1.24. The security team wants to enforce that all pods run with a read-only root filesystem. Which approach is most effective?
Trap 1: Use OPA Gatekeeper to deny pods without readOnlyRootFilesystem
While possible, OPA Gatekeeper is an external tool; the question asks for the most effective built-in approach.
Trap 2: Enable PodSecurityPolicy with readOnlyRootFilesystem: true
PodSecurityPolicy is deprecated but still available in Kubernetes 1.24 and is scheduled for removal in 1.25. Although it can enforce readOnlyRootFilesystem, it is not the most effective forward-looking approach compared to the built-in PodSecurity admission controller with the restricted profile.
Trap 3: Set --read-only-port=0 in kubelet
This disables the read-only port but does not enforce read-only filesystem for containers.
- A
Use OPA Gatekeeper to deny pods without readOnlyRootFilesystem
Why it fails: While possible, OPA Gatekeeper is an external tool; the question asks for the most effective built-in approach.
- B
Enable PodSecurityPolicy with readOnlyRootFilesystem: true
Why it fails: PodSecurityPolicy is deprecated but still available in Kubernetes 1.24 and is scheduled for removal in 1.25. Although it can enforce readOnlyRootFilesystem, it is not the most effective forward-looking approach compared to the built-in PodSecurity admission controller with the restricted profile.
- C
Enable PodSecurity admission controller with restricted profile
The restricted profile enforces readOnlyRootFilesystem: true as part of the policy.
- D
Set --read-only-port=0 in kubelet
Why it fails: This disables the read-only port but does not enforce read-only filesystem for containers.