skip to content

Kubernetes Admission Control

You will learn to author the rule an admission request is judged by: the AdmissionReview it sees, the objects it matches, reject versus patch. Most admission accidents are authoring accidents.

on this pageshow

explore

questions

page 2 of 2

An eleven-month-old StatefulSet cannot scale up eight weeks after a PVC label policy shipped — what happened?

level: seniorimportance: should knowfreq 46%

basics

~20 s

The StatefulSet's volume claim template predates the policy and lacks the required label. Its existing replicas were never re-evaluated, but each new replica makes the controller create a fresh PVC, and that create is denied at admission.

open as a page

How would you enforce that a container never downloads and executes a binary after it has started?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Not at admission. Admission decides once, when the object is written, and a process fetching code an hour later produces no API request, so no rule runs. Admission can narrow what the workload is granted; only a runtime sensor can observe the act.

open as a page

An auditor asks what share of PersistentVolumeClaims carry the retention label and you have a 100%-pass admission dashboard — what do you report?

level: principalimportance: should knowfreq 38%

basics

~20 s

Report the count from an inventory of stored PVCs, not the dashboard. A 100% pass rate describes admission requests since the rule was enabled; the auditor asked about the population of objects that exist, which only enumerating them answers.

open as a page

Why does Kubernetes reject a ValidatingAdmissionPolicyBinding whose validationActions is [Deny, Warn]?

level: middleimportance: nice to knowfreq 28%

basics

~20 s

Deny already reports the failure in the API response the client receives, so adding Warn would repeat the identical text in a 299 warning header. Kubernetes disallows the pair as pointless duplication; Audit combines with either one.

open as a page

Why does a rule rejecting a Namespace without a companion NetworkPolicy block every namespace?

level: middleimportance: nice to knowfreq 31%

basics

~10 s

At admission time the NetworkPolicy cannot exist yet: it lives inside the namespace being created. The rule asks about a future state at the one instant it cannot be true, so it rejects everything.

open as a page

A Kubernetes admission rule exempts one username, yet still blocks that user's Deployment — why?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Because the exemption is checked against the requester, and the request that gets blocked is the Pod create — made by the ReplicaSet controller's service account, not by the person. The human's name only ever appears on the Deployment request.

open as a page

What does matchPolicy Equivalent do in a Kubernetes admission policy that Exact does not?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

Equivalent makes a rule fire even when a request arrives under an API version the rule did not list, converting the object first. Exact intercepts only the listed group, version and resource, so other served versions pass unevaluated.

open as a page

You diff a running Pod against the manifest you committed and find fields your team never wrote. What happened?

level: seniorimportance: nice to knowfreq 38%

basics

~20 s

An admission mutation patched the object before it was stored, so the cluster is compliant and the committed file is not. Confirm it with a server-side dry-run, then fix the manifest - the live object is not your source of truth.

open as a page

Why would the API server reject a ValidatingAdmissionPolicy for exceeding its CEL cost budget?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Kubernetes statically estimates each expression's worst-case evaluation cost when the policy object is written, and refuses it if the estimate exceeds the limit. Nested iteration over collections the schema does not bound is the usual cause.

open as a page

Your admission rule needs data from other cluster objects: should the engine get a standing cluster-wide read?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Only if the rule is worth the credential. An admission request carries no other object, so the engine must fetch state itself, and a standing cluster-wide read turns the enforcement plane into a cross-namespace reader and an escalation target.

open as a page

Before adopting an in-cluster policy engine, what do you require of its upgrade story and who owns it?

level: principalimportance: nice to knowfreq 40%

basics

~20 s

Name the team that will upgrade it and carry its pager before you install it. Require a rehearsable upgrade: pinned versions, documented schema changes to the policy resources, rule tests re-run first, and a back-out on-call can execute.

open as a page

You are asked a third time to add an admission rule for a fact the request never carries — what do you say?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Accept the requirement and refuse the placement. Name the fact that is missing from the request, name where it exists and who owns the check there, get the requirement recorded against that owner, and state on the coverage map that admission enforces nothing for it.

open as a page

showing 31–42 of 42