5G/6G Academy
5G/6G AcademyTelecom certifications · since 2009
Cloud-Native Telecom

Cloud-Native Telecom · Pro

Security: RBAC, network policies, pod security, secrets management

Pod Security Standards and Admission Control

Securing a 5G Core on Kubernetes requires defense in depth across multiple layers. Pod Security Standards define three profiles: Privileged, Baseline, and Restricted. Telecom control plane NFs should run under the Restricted profile, using non-root users, read-only root filesystems, and dropping all Linux capabilities. Data plane NFs like UPF may require the Baseline profile due to their need for specific capabilities like NET_ADMIN for SR-IOV and SYS_RESOURCE for hugepages. Pod Security Admission controllers enforce these standards at the namespace level, preventing deployment of pods that…

Continue reading with Pro

Your free trial has ended. Subscribe to unlock the full lesson plus all 26 advanced levels, 732 lessons, labs, and 17 TELCOMA certification exams.

From $99/year·7-day money-back guarantee·Cancel anytime