Kubernetes Admission Control
You will learn to author the rule an admission request is judged by: the AdmissionReview it sees, the objects it matches, reject versus patch. Most admission accidents are authoring accidents.
on this pageshowhide
explore
- The Intercepted Request18 questions
- AdmissionReview Contents3 questions
- Match Rules and Scoping4 questions
- Validate or Mutate3 questions
- Denials and Warnings4 questions
- Controller-Created Objects4 questions
- Writing Rules In-Cluster12 questions
- Expression Policy Ceiling4 questions
- The Engine You Maintain4 questions
- The Engine's Blast Radius4 questions
- Limits of Interception12 questions
- Objects Already Running4 questions
- Cross-Object Rules4 questions
- The Wrong Choke Point4 questions
questions
page 2 of 2An eleven-month-old StatefulSet cannot scale up eight weeks after a PVC label policy shipped — what happened?
basics
~20 sThe StatefulSet's volume claim template predates the policy and lacks the required label. Its existing replicas were never re-evaluated, but each new replica makes the controller create a fresh PVC, and that create is denied at admission.
How would you enforce that a container never downloads and executes a binary after it has started?
basics
~20 sNot at admission. Admission decides once, when the object is written, and a process fetching code an hour later produces no API request, so no rule runs. Admission can narrow what the workload is granted; only a runtime sensor can observe the act.
An auditor asks what share of PersistentVolumeClaims carry the retention label and you have a 100%-pass admission dashboard — what do you report?
basics
~20 sReport the count from an inventory of stored PVCs, not the dashboard. A 100% pass rate describes admission requests since the rule was enabled; the auditor asked about the population of objects that exist, which only enumerating them answers.
Why does Kubernetes reject a ValidatingAdmissionPolicyBinding whose validationActions is [Deny, Warn]?
basics
~20 sDeny already reports the failure in the API response the client receives, so adding Warn would repeat the identical text in a 299 warning header. Kubernetes disallows the pair as pointless duplication; Audit combines with either one.
Why does a rule rejecting a Namespace without a companion NetworkPolicy block every namespace?
basics
~10 sAt admission time the NetworkPolicy cannot exist yet: it lives inside the namespace being created. The rule asks about a future state at the one instant it cannot be true, so it rejects everything.
A Kubernetes admission rule exempts one username, yet still blocks that user's Deployment — why?
basics
~20 sBecause the exemption is checked against the requester, and the request that gets blocked is the Pod create — made by the ReplicaSet controller's service account, not by the person. The human's name only ever appears on the Deployment request.
What does matchPolicy Equivalent do in a Kubernetes admission policy that Exact does not?
basics
~20 sEquivalent makes a rule fire even when a request arrives under an API version the rule did not list, converting the object first. Exact intercepts only the listed group, version and resource, so other served versions pass unevaluated.
You diff a running Pod against the manifest you committed and find fields your team never wrote. What happened?
basics
~20 sAn admission mutation patched the object before it was stored, so the cluster is compliant and the committed file is not. Confirm it with a server-side dry-run, then fix the manifest - the live object is not your source of truth.
Why would the API server reject a ValidatingAdmissionPolicy for exceeding its CEL cost budget?
basics
~20 sKubernetes statically estimates each expression's worst-case evaluation cost when the policy object is written, and refuses it if the estimate exceeds the limit. Nested iteration over collections the schema does not bound is the usual cause.
Your admission rule needs data from other cluster objects: should the engine get a standing cluster-wide read?
basics
~20 sOnly if the rule is worth the credential. An admission request carries no other object, so the engine must fetch state itself, and a standing cluster-wide read turns the enforcement plane into a cross-namespace reader and an escalation target.
Before adopting an in-cluster policy engine, what do you require of its upgrade story and who owns it?
basics
~20 sName the team that will upgrade it and carry its pager before you install it. Require a rehearsable upgrade: pinned versions, documented schema changes to the policy resources, rule tests re-run first, and a back-out on-call can execute.
You are asked a third time to add an admission rule for a fact the request never carries — what do you say?
basics
~20 sAccept the requirement and refuse the placement. Name the fact that is missing from the request, name where it exists and who owns the check there, get the requirement recorded against that owner, and state on the coverage map that admission enforces nothing for it.
showing 31–42 of 42