create namespaces
A new namespace carries no Pod Security Admission label by default.
Without a restrictive cluster-wide PSA default set via AdmissionConfiguration (per-namespace labels don't cover it), the namespace starts fully permissive, even where every other namespace enforces baseline or restricted, and privileged pods run there immediately.
- API Group
- (core)
- Scope
- cluster
- Audit Level
- Request
Escalation Paths
With patch on namespaces, remove the pod-security.kubernetes.io/enforce label from an existing namespace, or set it to privileged, disabling PSA there
Or with create on namespaces, create a fresh namespace with no PSA label at all, which starts permissive
Either path assumes no restrictive cluster-wide default (AdmissionConfiguration).
With such a default, both fall back to it instead of to permissive
Create privileged pods freely in the now-unenforced namespace
Additional rights needed:
