violates PodSecurity ☸️ Kubernetes

Error creating: pods is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false ...

The namespace enforces a Pod Security Standard (baseline/restricted) and the pod spec breaks one of its rules.

Seen on: Kubernetes

Meaning

Pod Security Admission (replacing PodSecurityPolicy since 1.25) checks namespace labels pod-security.kubernetes.io/enforce. “restricted” requires runAsNonRoot, no privilege escalation, dropped capabilities and a seccomp profile.

Common causes

  • Container runs as root or allows privilege escalation
  • Missing seccompProfile / capabilities not dropped
  • hostPath, hostNetwork or privileged containers in a baseline/restricted namespace

⚡ Quick fix

  1. Add the required securityContext
  2. Run the image as a non-root user
  3. Relax the namespace label only if appropriate

Detailed fix by platform

YAML

  1. bash
    securityContext:
      runAsNonRoot: true
      allowPrivilegeEscalation: false
      capabilities: { drop: ["ALL"] }
      seccompProfile: { type: RuntimeDefault }

How to diagnose

  1. Namespace — kubectl get ns app --show-labels
  2. Violations — Listed rules in the message

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.