[Verse 1]
When you're setting up your pod today
Security context shows the way
Run as non-root, that's the rule
User ID one thousand is your tool
Read-only root filesystem's the key
No privilege escalation, you see
[Chorus]
Lock it down, lock it down
Security context all around
Drop all caps and add back what you need
Read-only roots will make you succeed
Lock it down, lock it down
Keep your pods safe and sound
[Verse 2]
Allow privilege escalation false
That's the setting that never faults
Capabilities drop them all
Then add back just what you call
SecComp profile runtime default mode
That's the safest way to code
[Chorus]
Lock it down, lock it down
Security context all around
Drop all caps and add back what you need
Read-only roots will make you succeed
Lock it down, lock it down
Keep your pods safe and sound
[Bridge]
Best practices tell us what to do
Pod security standards guide you through
Scan your images in CI CD flow
Before they reach your cluster, you know
Namespace level standards are the way
Keep vulnerabilities at bay
[Verse 3]
Run as non-root true is set
Read-only filesystem's your best bet
User one thousand runs your code
Security context shares the load
Drop all capabilities clean
Add back only what you need
[Chorus]
Lock it down, lock it down
Security context all around
Drop all caps and add back what you need
Read-only roots will make you succeed
Lock it down, lock it down
Keep your pods safe and sound
[Outro]
Security context in your spec
Keeps your cluster systems in check
Lock it down and sleep at night
Your pods are running safe and right