Error creating: pods is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false ...
The namespace enforces a Pod Security Standard (baseline/restricted) and the pod spec breaks one of its rules.
Seen on:
Kubernetes
Meaning
Pod Security Admission (replacing PodSecurityPolicy since 1.25) checks namespace labels pod-security.kubernetes.io/enforce. “restricted” requires runAsNonRoot, no privilege escalation, dropped capabilities and a seccomp profile.
Common causes
- Container runs as root or allows privilege escalation
- Missing seccompProfile / capabilities not dropped
- hostPath, hostNetwork or privileged containers in a baseline/restricted namespace
⚡ Quick fix
- Add the required securityContext
- Run the image as a non-root user
- Relax the namespace label only if appropriate
Detailed fix by platform
YAML
- bash
securityContext: runAsNonRoot: true allowPrivilegeEscalation: false capabilities: { drop: ["ALL"] } seccompProfile: { type: RuntimeDefault }
How to diagnose
- Namespace — kubectl get ns app --show-labels
- Violations — Listed rules in the message
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 1005 Cloudflare Error 1005: Access denied — The owner of this website has banned the autonomous system number (ASN) your IP address is in
- 1006 Cloudflare Error 1006 / 1007 / 1008: Access denied — Your IP address has been banned
- 403 Forbidden wp-admin WordPress: 403 Forbidden on wp-admin, wp-login.php or admin-ajax.php
Most viewed in Kubernetes
- error converting YAML to JSON error converting YAML to JSON: yaml: line 12: did not find expected key
- kubectl connection refused kubectl: The connection to the server localhost:8080 was refused — did you specify the right host or port?
- CreateContainerConfigError Kubernetes: CreateContainerConfigError — secret / configmap not found
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026