Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

**Deprecating** May 3rd 2021: Support for Pod Security Policies (preview) #968

Closed
jnoller opened this issue May 13, 2019 · 10 comments
Closed
Assignees

Comments

@jnoller
Copy link
Contributor

jnoller commented May 13, 2019

Pod security policy (preview) will be deprecated on February 1st, 2021. This deadline has been extended from the initial deprecation date of October 15th, 2020 to provide more time to migrate to Azure Policy / OPA solutions.

  • Impacted customers with existing preview clusters enabled with pod security policy (preview) were sent the communication email via admin emails on July 13th for the initial deprecation notice.
    • The follow-up extension of the deadline was sent on September 10th, 2020 moving the deprecation to 02/01/2021.
  • AKS release notes announced the initial deprecation warning in 2020-07-06.
  • Existing PSP document contains a warning with details.
  • The succeeding feature, Azure Policy for AKS contains a deep dive document for pod security through Policy for AKS.
@claudod
Copy link

claudod commented Oct 28, 2019

Hi, thanks for this feature. The ordinary question: any idea on the ETA for GA ?

@sauryadas
Copy link
Contributor

I doubt this will go GA given that there are plans to deprecate PSP upstream and roll it up with Azure Policy that leverages both OPA/Gatekeeper.

Deprecation is not finalized yet.. Take a look at the June 19th comments in the thread below
kubernetes/enhancements#5

@jluk jluk removed the roadmap label Apr 8, 2020
@ferantivero
Copy link

ferantivero commented Apr 27, 2020

@jluk may I ask what this label roadmap removal means for now?

@jluk
Copy link
Contributor

jluk commented Apr 27, 2020

The roadmap label was a duplicate of feature label, so the removal doesn't mean anything in particular.

PSP is a unique case though, in that the upstream community is not showing signs of moving this feature to stable which would block AKS from making it GA. For the future of PSP the trends point to OPA/Gatekeeper to replace it over time. You can look to the Azure Policy for AKS addon which implements OPA/GK in a cluster on your behalf in a managed fashion.

https://docs.microsoft.com/en-us/azure/governance/policy/concepts/rego-for-aks

@jluk
Copy link
Contributor

jluk commented Jul 17, 2020

Pod security policy (preview) will be deprecated on October 15th, 2020.

@jluk jluk changed the title Support for Pod Security Policies (PSPs) **Deprecating** October 15th, 2020: Support for Pod Security Policies (preview) Jul 17, 2020
@alextrs
Copy link

alextrs commented Aug 4, 2020

PSP doesn't just validate that pod is in compliance it also can set defaults. Azure Policy for AKS only can deny or audit deployment. It is very painful to go deployment by deployment and make sure securityContext is set correctly, and for many operators even impossible. Is there a way to set defaults with Azure Policy for AKS?

@ritazh
Copy link
Member

ritazh commented Aug 21, 2020

Thanks for the feedback @alextrs. I am one of the maintainers of the Gatekeeper project. Currently the Gatekeeper project is focusing on getting the admission side of things to stable as those seem to be the most broadly useful features from a security perspective. Mutation is significantly more complex than validation. It is in the project's backlog. I will share updates here once there's more progress with mutation.

@jluk jluk assigned ritazh and jluk and unassigned sauryadas Sep 4, 2020
@jluk jluk changed the title **Deprecating** October 15th, 2020: Support for Pod Security Policies (preview) **Deprecating** February 1st, 2021: Support for Pod Security Policies (preview) Sep 10, 2020
@PrabhuMathi
Copy link

Good news but still still why deprecating and it? it is better to leave it with user itself!

@miwithro miwithro self-assigned this Oct 23, 2020
@miwithro miwithro changed the title **Deprecating** February 1st, 2021: Support for Pod Security Policies (preview) **Deprecating** May 3rd 2021: Support for Pod Security Policies (preview) Oct 23, 2020
@ghost ghost added the stale Stale issue label Dec 22, 2020
@Azure Azure deleted a comment Dec 22, 2020
@ghost ghost removed the stale Stale issue label Dec 22, 2020
@miwithro miwithro reopened this Dec 22, 2020
@ghost ghost added the stale Stale issue label Feb 21, 2021
@ghost
Copy link

ghost commented Feb 21, 2021

This issue has been automatically marked as stale because it has not had any activity for 60 days. It will be closed if no further activity occurs within 15 days of this comment.

@ghost ghost closed this as completed Mar 8, 2021
@ghost
Copy link

ghost commented Mar 8, 2021

This issue will now be closed because it hasn't had any activity for 15 days after stale. jnoller feel free to comment again on the next 7 days to reopen or open a new issue after that time if you still have a question/issue or suggestion.

@ghost ghost locked as resolved and limited conversation to collaborators Apr 7, 2021
This issue was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

10 participants