Rules applied before objects are created.
WHAT ADMISSION CONTROL IS
Checking or modifying objects as they are submitted.
WHAT IT ENFORCES
Requirements nobody should be able to bypass.
WHAT EXAMPLES LOOK LIKE
No containers running as root Resource limits required Images only from approved registries Required labels present No privileged containers
WHY ENFORCE RATHER THAN DOCUMENT
Documented rules are forgotten under pressure.
WHAT VALIDATING POLICIES DO
Reject objects breaking a rule.
WHAT MUTATING POLICIES DO
Modify them, adding defaults.
WHAT TO BE CAREFUL WITH
Mutation, since objects differ from what was submitted.
WHY THAT CONFUSES PEOPLE
The running object does not match the file.
WHAT TO START WITH
A small number of rules, in warning mode.
WHY WARNING FIRST
It reveals what would break before it does.
WHAT TO ENFORCE ONCE STABLE
The rules that genuinely matter.
WHAT TO TEST
That the policy engine failing does not block all deployments.
WHY THAT MATTERS
A failed policy webhook can prevent anything being created.
WHAT TO SET
A failure policy appropriate to the rule's importance.
WHAT TO DOCUMENT
Every rule, with the reason and how to request an exception.