Admission control

Admission control is the last moment the cluster can say no before a workload exists.

It inspects what is being created and can reject or modify it: no privileged containers, no images from unapproved registries, required labels. Because it runs before anything is scheduled, it prevents rather than detects, which is a stronger position than anything downstream.

Checked against the primary source.

More on Containers & Kubernetes