Definition. A three-level profile model that Kubernetes uses to check pods for permitted security properties: privileged (everything allowed), baseline (prevents the most obvious escalations) and restricted (heavily hardened, close to best practice). They replace the older PodSecurityPolicy and are enforced per namespace via a label.
Why it matters. Without actively set standards, containers in Kubernetes run with far more privileges than they need. restricted is a realistic target for most applications and closes common container escape vectors.
Related. Container Escape, Kubernetes Worker Node, Runtime Security, Kernel Hardening