Kubernetes introduced external admission control in v1.7 to allow administrators to define policies for what objects can be admitted into a cluster.
One way to enforce these policies is through validating admission policies, which use the Common Expression Language (CEL) to declare validation rules.
Kubescape, a CNCF project for Kubernetes cluster security, has converted many of its controls to CEL and built a library of validating admission policies, which can be installed in a Kubernetes cluster using a selector and applied to objects using a ValidatingAdmissionPolicyBinding resource.
This feature is currently in alpha and not yet production-ready, but it is a promising native solution for enforcing policies in a Kubernetes cluster.
Let's keep in touch!
Stay updated with my latest posts and news. I share insights, updates, and exclusive content.
Unsubscribe anytime. By subscribing, you share your email with @faun and accept our Terms & Privacy.
Give this a Pawfive!
Only registered users can post comments. Please, login or signup.
Start writing about what excites you in tech — connect with developers, grow your voice, and get rewarded.
Join other developers and claim your FAUN.dev() account now!
The FAUN watches over the forest of developers. It roams between Kubernetes clusters, code caves, AI trails, and cloud canopies, gathering the signals that matter and clearing out the noise.
Developer Influence
0
Influence
441k
Total Hits
3711
Posts
Hey, sign up or sign in to add a reaction to my post.
Join thousands of other developers, 100% free, leave anytime.
Hey there! 👋 I created FAUN.dev(), an effortless, straightforward way for busy developers to keep up with the technologies they love 🚀
Aymen @eon01
Founder of FAUN.dev()
Join thousands of developers and engineering teams who use FAUN.dev() to stay up-to-date with the technologies they love, without the overwhelm.