Decide which isolation rules the API server checks, which protections require prepared nodes, and which resource costs appear only when a Pod runs. Validate a replacement workload before enforcing a new policy.
Review these lessons
- Pod Security Admission: stage warnings before a namespace denies Pods
- Seccomp RuntimeDefault: test syscall behavior across node runtimes
- AppArmor profiles: match Pod placement to actual node enforcement
- Supplemental groups: remove unexpected access inherited from an image
- Read-only root filesystems: inventory every required write path
- Pod user namespaces: verify host mapping and volume compatibility
- RuntimeClass: budget the real cost of a stronger sandbox
- Local ephemeral storage: account for logs, writable layers, and emptyDir
Other checks
Common Mistakes
- Do not infer node enforcement from an admitted manifest.
- Do not omit runtime overhead and scratch use from capacity planning.
