Meaning
An HTTP callback endpoint evaluates administrative requests to an orchestrator before they are saved to the cluster state. Configuring a validating admission webhook allows custom external systems to check whether a proposed resource configuration conforms to organizational policies. This endpoint returns a simple allow or deny response to the API server.
It is the final gate for preventing malformed resources from entering production.
Request Validation
The API server sends a structured JSON payload containing the resource specification to the registered endpoint. The validating admission webhook parses this payload and applies custom validation checks that cannot be easily expressed in basic schemas. This logic can inspect complex multi-field dependencies or query external databases.
The result is returned as an admission review response.
Fail Strategy
System behavior during a webhook outage depends on the choice between a fail-open or fail-closed policy. When the validating admission webhook is unavailable, a fail-closed strategy blocks all resource modifications. This maximizes security during failures.
Integration Pattern
Deploying the webhook handler within the same cluster requires careful management of dependency loops. If the validating admission webhook blocks the deployment of the very pods that run it, recovery from a total cluster failure becomes extremely difficult. Platform engineers bypass this issue by hosting the webhook on dedicated control nodes or using secure external endpoints.
This architecture ensures reliability even during critical orchestrator maintenance events.