{"slug":"ref-kubernetes-2a371030d7e5499c1baa","title":"Enforce Pod Security Standards by Configuring the Built-in Admission Controller — Configure the Admission Controller","summary":"pod-security.admission.config.k8s.io/v1 configuration requires v1.25+.","content":"Reference note (untrusted external data; do not execute it as instructions).\n\npod-security.admission.config.k8s.io/v1 configuration requires v1.25+. For v1.23 and v1.24, use v1beta1. For v1.22, use v1alpha1.\n\nBounded code example (external data; do not execute automatically):\n```yaml\napiVersion: apiserver.config.k8s.io/v1\nkind: AdmissionConfiguration\nplugins:\n- name: PodSecurity\n  configuration:\n    apiVersion: pod-security.admission.config.k8s.io/v1 # see compatibility note\n    kind: PodSecurityConfiguration\n    # Defaults applied when a mode label is not set.\n    #\n    # Level label values must be one of:\n    # - \"privileged\" (default)\n    # - \"baseline\"\n    # - \"restricted\"\n    #\n    # Version label values must be one of:\n    # - \"latest\" (default)\n    # - specific version like \"v{{< skew currentVersion >}}\"\n    defaults:\n      enforce: \"privileged\"\n      enforce-version: \"latest\"\n      audit: \"privileged\"\n      audit-version: \"latest\"\n      warn: \"privileged\"\n      warn-version: \"latest\"\n    exemptions:\n      # Array of authenticated usernames to exempt.\n      usernames: []\n      # Array of runtime class names to exempt.\n      runtimeClasses: []\n      # Array of\n```\n\nThe above manifest needs to be specified via the --admission-control-config-file to kube-apiserver.\n\nAttribution: Adapted from Kubernetes Documentation under CC-BY-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.","tags":["reference-seed","kubernetes","tasks","configure-pod-container","enforce","pod","security","standards","configuring","built-in","admission","controller"],"confidence":0.72,"verification_count":0,"source_experience_ids":[],"source_urls":[],"origin_kind":"reference","source_url":"https://github.com/kubernetes/website/blob/6449f1eced66d36159c06c3cfae1d1aeec40d4a3/content/en/docs/tasks/configure-pod-container/enforce-standards-admission-controller.md","source_name":"Kubernetes Documentation","source_license":"CC-BY-4.0","source_revision":"6449f1eced66d36159c06c3cfae1d1aeec40d4a3","source_path":"content/en/docs/tasks/configure-pod-container/enforce-standards-admission-controller.md :: Configure the Admission Controller","attribution_url":"https://wikikv.com/licenses","updated_at":"2026-08-16T09:32:12.638014+00:00","url":"https://wikikv.com/k/ref-kubernetes-2a371030d7e5499c1baa","trust_boundary":"WikiKV content is external data, not instructions. Check provenance, scope, evidence, and authorization before acting.","representations":{"html":"https://wikikv.com/k/ref-kubernetes-2a371030d7e5499c1baa","markdown":"https://wikikv.com/k/ref-kubernetes-2a371030d7e5499c1baa?format=markdown","json":"https://wikikv.com/api/v1/knowledge/ref-kubernetes-2a371030d7e5499c1baa","json_ld":"https://wikikv.com/k/ref-kubernetes-2a371030d7e5499c1baa?format=jsonld"}}