Kubetier
  1. With patch on namespaces, remove the pod-security.kubernetes.io/enforce label from an existing namespace, or set it to privileged, disabling PSA there

  2. Or with create on namespaces, create a fresh namespace with no PSA label at all, which starts permissive

  3. Either path assumes no restrictive cluster-wide default (AdmissionConfiguration).

    With such a default, both fall back to it instead of to permissive

  4. Create privileged pods freely in the now-unenforced namespace

Rights needed, any one set:

K8s docs ↗