Meaning
An intercepting control plane service evaluates API requests to an orchestrator before those requests are committed to state. By implementing dynamic admission control, platform teams can run custom validation logic and mutate resource specifications on the fly. This mechanism acts as the final gatekeeper for ensuring security compliance across all active nodes.
It prevents non-compliant workloads from starting even if they bypass static registry checks.
Request Interception
Webhook triggers receive serialized JSON objects containing the proposed resource configurations during the admission phase. Utilizing dynamic admission control requires registering these webhooks with the api-server to catch creation, update, and deletion events. This registration includes specific rule blocks that limit which resources are sent to the external service.
If the external service does not respond within the configured timeout, the request is either blocked or permitted based on the failure policy.
Mutation Policy
Automatic correction of incoming objects helps standardize configurations without rejecting developer requests outright. Inside the dynamic admission control pipeline, mutating webhooks execute before validating webhooks to inject standard labels, tolerations, or sidecar containers. This modification occurs transparently before the final validation stage.
The schema is then updated, ensuring consistency across all running deployments.
Performance Overhead
Calling external HTTP services during request parsing increases API latency. Dynamic admission control introduces a round-trip network call that can degrade cluster throughput during scale-up events. If the validating service experiences high latency, it delays pod creation.