# Longhorn Manager uses hostPath + privileged; incompatible with Pod Security "baseline". # Apply before or after Helm — merges labels onto existing longhorn-system. apiVersion: v1 kind: Namespace metadata: name: longhorn-system labels: pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/warn: privileged