Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Kubernetes admission policy: reject an unsafe workload before scheduling

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

A ValidatingAdmissionPolicy evaluates matched Kubernetes API requests with CEL expressions. A binding decides where the policy applies and whether a failure is denied, warned, or audited. It can reject a manifest before it reaches a controller; it does not inspect the image's actual contents or prove that an allowed deployment is healthy.

Operational decision

For a payments namespace, require every Deployment container image reference to include a digest marker. Start with a warning binding, inventory the existing violations, and only then switch to denial. The sample includes the policy and a binding scoped to namespaces carrying an explicit enforcement label. The expression checks for the marker, not a full 64-character digest or trusted registry; a production policy should validate the complete reference and pair it with signed-provenance verification. Test CREATE and UPDATE requests, sidecars, and emergency rollback manifests. A fail-closed policy protects the boundary but can block incident mitigation if no approved prior digest exists. Record an exception process with a narrow scope and expiry rather than removing admission controls for the whole cluster.

yaml
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata: {name: require-deployment-digests}
spec:
  failurePolicy: Fail
  matchConstraints:
    resourceRules:
      - apiGroups: [apps]
        apiVersions: [v1]
        operations: [CREATE, UPDATE]
        resources: [deployments]
  validations:
    - expression: 'object.spec.template.spec.containers.all(c, c.image.contains("@sha256:"))'
      message: Container images need a digest reference
---
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicyBinding
metadata: {name: require-deployment-digests-payments}
spec:
  policyName: require-deployment-digests
  validationActions: [Warn]
  matchResources:
    namespaceSelector:
      matchLabels: {policy-tier: payment-enforced}

Cost and verification

CEL evaluation costs control-plane work on matched API calls, so keep expressions focused and test admission latency. A Warn action does not block unsafe Deployments; change to Deny only after the inventory and rollback path are ready. Namespace labels are part of the policy boundary and need controlled edit rights. The example does not cover initContainers or ephemeralContainers and only checks for a substring, so it must not be presented as complete image integrity enforcement. An admission failure is a configuration result, not a runtime health signal.

Common Mistakes

  • Do not mistake Warn for enforcement.
  • Do not claim a digest substring proves image provenance.
  • Do not block rollback without a safe approved revision.

Connected lessons

Advanced follow-up

Advanced follow-up

Advanced follow-up

Advanced follow-up

devops
operations
Storage details