Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A platform engineering team is setting up a new Kubernetes cluster and needs to define custom security policies that go beyond standard Pod Security Standards (PSS). Specifically, they want to disallow deployments that use a root filesystem and require all container images to be from a specific internal registry. Which Kubernetes extension point is most suitable for enforcing these custom rules at the point of resource creation or update?

  1. ACustom Resource Definitions (CRDs)
  2. BResourceQuotas
  3. CValidating Admission Webhooks
  4. DMutating Admission Webhooks
Show answer & explanation

Correct answer: C. Validating Admission Webhooks

Validating Admission Webhooks are HTTP callbacks that receive admission requests and can reject them based on custom logic. This is ideal for enforcing policies like disallowing root filesystems or requiring specific image registries, as they can prevent non-compliant resources from being persisted in the cluster.

Why the other options are wrong

  • A. CRDs define new resource types, not policy enforcement mechanisms.
  • B. ResourceQuotas limit resource consumption (CPU, memory, storage) in a namespace, not custom security policies on resource attributes.
  • D. Mutating Admission Webhooks can change objects before they are persisted, but the primary goal here is to *reject* non-compliant objects, which is the role of a Validating webhook.

Validating Admission Webhooks

Kubernetes admission controllers that are configured as HTTP callbacks. They intercept API requests and can reject them if they violate custom defined rules, thus enforcing policies before resources are persisted.

  • Intercepts API requests before persistence.
  • Can reject requests based on custom logic.
  • Used for enforcing security policies and compliance.

Memory trick: Admission controllers are the gatekeepers, webhooks are their custom rulebooks.

More Cloud Native Security questions