Kubetier
← Permission Reference
T1

create namespaces

A new namespace carries no Pod Security Admission label by default.

A new namespace starts fully permissive, so privileged pods run there at once, even where every other namespace enforces baseline or restricted.

Only a cluster-wide PSA default set through AdmissionConfiguration prevents this, since per-namespace labels do not cover it.

API Group
(core)
Scope
cluster
Audit Level
Request

Escalation Paths

  1. With patch on namespaces, remove the pod-security.kubernetes.io/enforce label from an existing namespace, or set it to privileged, disabling PSA there

  2. Or with create on namespaces, create a fresh namespace with no PSA label at all, which starts permissive

  3. Either path assumes no restrictive cluster-wide default (AdmissionConfiguration).

    With such a default, both fall back to it instead of to permissive

  4. On its own this only removes a guard.

    Creating the privileged pod needs a pods create verb, which this path does not include

Additional rights needed:

none
K8s docs ↗
K8s docs ↗