A ValidatingAdmissionPolicy evaluates matched Kubernetes API requests with CEL expressions. A binding decides where the policy applies and whether a failure is denied, warned, or audited. It can reject a manifest before it reaches a controller; it does not inspect the image's actual contents or prove that an allowed deployment is healthy.
Kubernetes admission policy: reject an unsafe workload before scheduling
Operational decision
For a payments namespace, require every Deployment container image reference to include a digest marker. Start with a warning binding, inventory the existing violations, and only then switch to denial. The sample includes the policy and a binding scoped to namespaces carrying an explicit enforcement label. The expression checks for the marker, not a full 64-character digest or trusted registry; a production policy should validate the complete reference and pair it with signed-provenance verification. Test CREATE and UPDATE requests, sidecars, and emergency rollback manifests. A fail-closed policy protects the boundary but can block incident mitigation if no approved prior digest exists. Record an exception process with a narrow scope and expiry rather than removing admission controls for the whole cluster.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata: {name: require-deployment-digests}
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups: [apps]
apiVersions: [v1]
operations: [CREATE, UPDATE]
resources: [deployments]
validations:
- expression: 'object.spec.template.spec.containers.all(c, c.image.contains("@sha256:"))'
message: Container images need a digest reference
---
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicyBinding
metadata: {name: require-deployment-digests-payments}
spec:
policyName: require-deployment-digests
validationActions: [Warn]
matchResources:
namespaceSelector:
matchLabels: {policy-tier: payment-enforced}Cost and verification
CEL evaluation costs control-plane work on matched API calls, so keep expressions focused and test admission latency. A Warn action does not block unsafe Deployments; change to Deny only after the inventory and rollback path are ready. Namespace labels are part of the policy boundary and need controlled edit rights. The example does not cover initContainers or ephemeralContainers and only checks for a substring, so it must not be presented as complete image integrity enforcement. An admission failure is a configuration result, not a runtime health signal.
Common Mistakes
- Do not mistake Warn for enforcement.
- Do not claim a digest substring proves image provenance.
- Do not block rollback without a safe approved revision.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Software supply chain: SBOM and provenance at admission
- Kubernetes RBAC: bind one service account to one job
- Immutable artifacts and release provenance
