Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A platform engineering team is setting up a new Kubernetes cluster and needs to implement custom security policies that are not covered by built-in admission controllers (like Pod Security Admission). For example, they want to reject any Pod deployment that uses a container image from an unapproved registry or does not have specific security labels. Which Kubernetes mechanism allows them to intercept API requests and apply such custom validation logic?

  1. ACustom Resource Definitions (CRDs)
  2. BKubernetes Audit Logs
  3. CValidating Admission Webhooks
  4. DResource Quotas
Show answer & explanation

Correct answer: C. Validating Admission Webhooks

Validating Admission Webhooks allow cluster administrators to configure external HTTP callbacks that intercept API requests (like Pod creation) and perform custom validation logic. If the webhook rejects the request, the API server denies the operation.

Why the other options are wrong

  • A. CRDs define new custom resources in Kubernetes but do not, by themselves, implement admission control logic.
  • B. Kubernetes Audit Logs record events after they occur, they do not prevent or modify API requests.
  • D. Resource Quotas limit resource consumption (CPU, memory) in a namespace, not custom security policies for Pods.

Validating Admission Webhooks

A Kubernetes admission controller that allows for custom, dynamic validation of API requests. It sends API requests to an external service (webhook) for evaluation before objects are persisted.

  • Intercepts API requests for validation.
  • Uses an external HTTP callback service.
  • Can reject requests if they violate custom policies.
  • Extends Kubernetes' built-in admission control.

Memory trick: Webhooks validate custom rules before admission.

More Cloud Native Security questions