Pod security
Pod-level restrictions limit what a workload may do to the host: run as root, mount host paths, use host networking, add capabilities.
They are where most escape prevention actually happens, because most escapes rely on excess privilege rather than on a kernel flaw. Applying a restrictive baseline by default and requiring justification to relax it is considerably easier than reviewing each workload.
Checked against the primary source.
