WEBBOOK CHAPTER

Kubernetes, 배포보다 운영이 어렵다: 31장. Admission policy 설계

31장. Admission policy 설계

production namespace에서 privileged, hostPath·hostNetwork, root, mutable tag, resource 누락, 승인되지 않은 registry, 과도한 capability를 차단한다. 처음부터 enforce해 기존 workload를 멈추지 않고 audit·warn에서 위반 inventory와 owner를 정리한다.

정책에는 목적, 적용 범위, 예외 주체, 만료, test fixture가 있다. platform component의 정당한 예외를 전체 namespace 면제로 만들지 않는다. policy engine 자체 장애 때 fail-open·closed가 deployment와 긴급 복구에 미치는 영향을 결정한다. 변경은 positive·negative manifest와 dry-run 결과를 증거로 남긴다.