apiVersion: v1 kind: Namespace metadata: name: sish labels: # hostNetwork is only permitted by the privileged profile. # The pod itself still runs non-root with all capabilities dropped. pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: baseline