CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The organization requires that all container images deployed to the cluster must originate from trusted, scanned repositories and meet specific security baselines. The auditor needs to identify the Kubernetes admission controller that can enforce these policies by intercepting and validating pod creation requests before they are persisted in the cluster's etcd database. Which admission controller is MOST relevant to this requirement?
- AServiceAccount
- BNodeRestriction
- CImagePolicyWebhook
- DLimitRanger
Show answer & explanationAnswer & explanation
Correct answer: C. ImagePolicyWebhook
The ImagePolicyWebhook admission controller allows an external HTTP webhook to validate image names and tags during pod creation, ensuring that only trusted and compliant images are deployed, directly addressing the requirement for trusted, scanned repositories.
Why the other options are wrong
- A. ServiceAccount manages service accounts and their tokens, unrelated to image validation.
- B. NodeRestriction limits the API objects a Kubelet can modify, which is not directly related to image policy enforcement.
- D. LimitRanger enforces resource limits (CPU, memory) on pods and containers within a namespace, not image origin.
ImagePolicyWebhook
A Kubernetes admission controller that intercepts requests to create pods and validates their container images against an external webhook service.
- Enforces image security policies
- Prevents deployment of untrusted images
- Integrates with external image registries/scanners
Memory trick: Admission Controllers Check Pods Before They Cruise.