Manifest-Based Admission Control in Kubernetes
How to use manifest-based admission control in Kubernetes v1.36 to close bootstrap and self-protection gaps in admission policies and webhooks.
How to use manifest-based admission control in Kubernetes v1.36 to close bootstrap and self-protection gaps in admission policies and webhooks.
How to migrate away from the deprecated Service .spec.externalIPs field in Kubernetes 1.36 and block its reuse with the DenyServiceExternalIPs admission controller.
How attackers exploit misconfigured Kubernetes admission controllers and insecure webhooks to bypass security policies.
How to enforce security defaults using MutatingAdmissionPolicy, the CEL-based in-process alternative to mutating admission webhooks, GA in Kubernetes v1.36.
Learn how Kubernetes Pod Security Standards (PSS) enforce security controls for workloads and replace the deprecated Pod Security Policies (PSP).