Admission control can stop risky objects before they run
Blocking a bad configuration at creation is the difference between prevention and investigation.
A policy that refuses privileged pods means none exist. A dashboard listing privileged pods means somebody has to notice and act. Both are described as controls; only one of them changes what is running in your cluster.
More on Kubernetes
- A container is isolation, not a tiny virtual machinePartitions, not buildings
- Kubernetes RBAC controls API actions, not what a running container can then doChecked at the hatch, not inside the room
- A pod service account is an identityA badge on the same rail
- NetworkPolicy needs an enforcement engineHinges, but no gate
- Privileged containers weaken the host boundaryThe floor is the boundary
- Mutable image tags can move underneath youSame ticket, different coat
