From 5f5934aee43889371d5d82db595d4236cc92eb59 Mon Sep 17 00:00:00 2001 From: Mauren Berti <698465+stormqueen1990@users.noreply.github.com> Date: Wed, 19 Apr 2023 11:49:54 -0400 Subject: [PATCH] Add admonition for caveat on finding PSPs in use Add a caution admonition for a caveat on using the kubectl get psp strategy to find which PSPs are still in use in the cluster. --- .../pod-security-standards.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md index e5b7448761a..7e74443f907 100644 --- a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md +++ b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md @@ -24,6 +24,10 @@ You must perform the following steps _while still in Kubernetes v1.24_: 1. Map your active PSPs to Pod Security Standards: 1. See which PSPs are still active in your cluster: + :::caution + This strategy might miss workloads that are not currently running, such as CronJobs, workloads that scale to zero, or workloads that have not rolled out yet. + ::: + ```shell kubectl get pods \ --all-namespaces \