Learning · Kubernetes

Admission and policy

Validating/mutating admission, Pod Security, and policy engines — enforcing defaults before bad objects land.

RBAC decides who may talk to the API. Admission decides whether the object is allowed to exist as written.

Admission chain

After authz, mutating webhooks/policies can rewrite objects (inject sidecars, defaults). Validating webhooks/policies accept or reject. Fail-closed vs fail-open for webhook outages is a production-critical choice — a dead validating webhook can block all deploys.

Pod Security

Pod Security Admission (privileged / baseline / restricted) encodes common hardening. Prefer restricted for product namespaces; reserve privileged for system components that truly need it.

Policy engines

OPA Gatekeeper, Kyverno, and cloud policy add-ons encode org rules: approved registries, required labels, banned hostPath, etc. Keep policies versioned and tested — a bad ConstraintTemplate is a cluster-wide outage.

What belongs in policy vs review

Automate mechanical rules (no :latest, must set requests, must run as non-root). Leave design judgment to humans. Policy that tries to encode product architecture becomes unmaintainable.

Change management

Policy changes need dry-run, staged rollout, and an owner. Surprising producers with a new reject rule on Friday breaks trust in the platform.

← Kubernetes