Problem
Kubernetes admission controller model that evaluates pod specifications against the restricted Pod Security Standard plus operational rules, rendering deny, warn, and pass verdicts with the enforcement and audit-mode difference made explicit.