* Only allow a user to run containers under his specific Linux user account (https://kubernetes.io/docs/concepts/policy/pod-security-policy/#users-and-groups) * Only allow hostPath mounting of home directory and scratch (https://kubernetes.io/docs/concepts/policy/pod-security-policy/#volumes-and-file-systems)