Pod security

Pod-level restrictions limit what a workload may do to the host: run as root, mount host paths, use host networking, add capabilities.

They are where most escape prevention actually happens, because most escapes rely on excess privilege rather than on a kernel flaw. Applying a restrictive baseline by default and requiring justification to relax it is considerably easier than reviewing each workload.

Checked against the primary source.

More on Containers & Kubernetes