Problem Statement
Which control reduces risky containers in Kubernetes?
Explanation
PSS policies block privileged containers, host mounts, and risky capabilities. Start with baseline and aim for restricted for most workloads.
Code Solution
SolutionRead Only
kubectl label ns prod pod-security.kubernetes.io/enforce=restricted
