Admission Policy as Code thumbnail

Admission Policy as Code

By Richard Augenti

Express your security standards as admission policies, test them against manifests that should pass and manifests that should not, and roll them out in audit mode before they start blocking deployments.

Browse
Skill Level: Intermediate Duration: 60 min Policy as CodeKubernetesDevSecOps
Sign in to start

Free to browse. Takes about 60 minutes once you start.

Lab Overview

Your cluster accepts any deployment anyone submits - images pinned to :latest, containers running as root, pods with no resource limits. Code review is supposed to catch these, but review is people, and people miss things.

In this lab you move the rules into the cluster itself using native Kubernetes ValidatingAdmissionPolicies written in CEL, so a non-compliant deployment is rejected at the API server no matter how it was submitted. You also roll the policy out in audit mode first, which is how this is done without breaking every legitimate workload on day one.

Everything runs against a local kind cluster on your own lab VM. No external cluster is touched and no policy engine needs installing - this is the API server's own admission machinery.

What to Expect

  • Environment: a single Ubuntu machine you connect to over SSH, with a local kind cluster named lab already running and no admission policy in place.
  • Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
  • Local cluster only: the cluster lives on the lab VM and is thrown away with it. Nothing you apply can reach a real cluster.
  • Progress: your work is not saved. If the lab expires or you quit, the machine, the cluster and everything on them are destroyed.

What are hands-on labs?

A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.

Real tooling

The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.

Break it freely

Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.

Useful on Monday

Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.

Browse labs