← Policy catalog
</> Policy bundles · Apache-2.0

bundles

A bundle is a versioned set of policies plus the ValidatingAdmissionPolicyBindings that switch them on. Nothing is enforced until you label a namespace, so a bundle is safe to install and then roll out one namespace at a time.

bundles2 policies193 bindings780 licenseApache-2.0
// how it works

warn, audit, then enforce.

Every bundle ships three bindings per policy, one per mode, each keyed to its own namespace label. Installing the bundle changes nothing on its own — the label is the switch, and you move one namespace at a time.

Each bundle page lists its own three label keys — the two bundles use different label prefixes — plus the per-policy opt-out label and the exact kubectl lines.

// the bundles

pick a starting point.

Pod Security Admission is the Kubernetes Pod Security Standards, rewritten as native admission policies. cenroq Best Practices is broader: pod hardening plus RBAC, secrets, exposure and risky-configuration guardrails.

cenroq Best Practices

v0.2.0

Best practice validating admission bundle that enforces pod hardening, safer runtime defaults, and broader cluster guardrails (RBAC, secrets, exposure, and risky config restrictions) for a strong security baseline.

176 policies528 bindings176 of 176 bound
  • 16 Critical
  • 27 High
  • 99 Moderate
  • 34 Low
  • security.cenroq.io/warn
  • security.cenroq.io/audit
  • security.cenroq.io/enforce

Pod Security Admission

v1.36.0-cenroq

Pod Security Standards implemented as Validating Admission Policies, with the same levels (baseline and restricted).

84 policies252 bindings84 of 84 bound
  • 4 Critical
  • 14 High
  • 46 Moderate
  • 20 Low
  • pss.security.cenroq.io/warn
  • pss.security.cenroq.io/audit
  • pss.security.cenroq.io/enforce
// the toolkit

install bundles with kubeapt.

Downloading and applying YAML by hand works. kubeapt makes it repeatable: install a bundle, pin its version, scan a cluster for the gaps it would close, and validate before you enforce.