Nirmata Documentation
  • Home
  • Products
    Nirmata Kyverno Enterprise Nirmata Policy Manager Nirmata DevSecOps Platform
  • docs
    Get Started Cluster Management Application Management Policy Management Identity & Access Settings Policy Sets REST API Private Edition Release Notes
  • release
    V3.5.4 V3.9.0
  • Policy Sets
    • Pod Security Standards
      • Baseline profile
        • disallow-capabilities
        • disallow-host-namespaces
        • disallow-host-path
        • disallow-host-ports
        • disallow-host-process
        • disallow-privileged-containers
        • disallow-proc-mount
        • disallow-selinux
        • restrict-apparmor-profiles
        • restrict-seccomp
        • restrict-sysctls
      • Restricted profile
        • disallow-capabilities-strict
        • disallow-privilege-escalation
        • require-run-as-non-root
        • require-run-as-non-root-user
        • restrict-seccomp-strict
        • restrict-volume-types
  • Nirmata Documentation
  • Policy Sets
  • Pod Security Standards
  • Baseline profile

Baseline profile

The Baseline profile is aimed at ease of adoption for common containerized workloads while preventing known privilege escalations. It is targeted at application operators and developers of non-critical applications.

Click on each of the controls to know more about them.

  • disallow-capabilties
  • disallow-host-namespaces
  • disallow-host-path
  • disallow-host-ports
  • disallow-host-process
  • disallow-privileged-containers
  • disallow-proc-mount
  • disallow-selinux
  • restrict-apparmor-profiles
  • restrict-seccomp
  • restrict-sysctls

Pod Security Standards disallow-capabilities

© Copyright 2022, Nirmata