Mutating admission policy

변경형 어드미션 정책

An API server policy fills or changes resource fields before persistence.

···
html
<div class="stage" data-phase="0"><div class="title">ADMISSION MUTATION</div><div class="row admission"><div class="panel mono before">pod<br>limit: —</div><div class="policy panel">CEL<br>default</div><div class="panel mono after">pod<br>limit: —</div></div><div class="sub">request → policy → stored resource</div></div>
css
.stage{width:min(94vw,760px);height:min(88vh,330px);padding:clamp(9px,2.6vmin,20px);border:1px solid var(--line);border-radius:14px;background:var(--surface);font:600 clamp(12px,2.5vmin,16px)/1.3 "Pretendard Variable",Pretendard,-apple-system,BlinkMacSystemFont,"Apple SD Gothic Neo",sans-serif;display:flex;flex-direction:column;gap:clamp(6px,1.7vmin,12px);overflow:hidden;position:relative}.stage *{min-width:0}.stage .title{color:var(--accent);font-weight:800}.stage .sub{color:var(--muted)}.stage .row{display:flex;align-items:center;gap:clamp(5px,1.6vmin,12px)}.stage .panel{border:1px solid var(--line);border-radius:8px;background:var(--bg);padding:clamp(6px,1.6vmin,12px)}.stage .mono{font-family:ui-monospace,SFMono-Regular,monospace;font-size:clamp(12px,2.5vmin,15px)}.stage .grow{flex:1}.stage .on{color:var(--accent)}.admission{flex:1;justify-content:space-between}.admission .panel{width:30%;text-align:center}.policy{border-color:var(--accent)!important;color:var(--accent)}.stage[data-phase="1"] .policy{background:color-mix(in srgb,var(--accent) 18%,var(--surface));box-shadow:0 0 0 3px color-mix(in srgb,var(--accent) 16%,transparent)}.stage[data-phase="2"] .after{font-size:0;border-color:var(--accent)}.stage[data-phase="2"] .after:after{content:'pod  limit: 512Mi';font:600 clamp(12px,2.5vmin,15px) ui-monospace,monospace;color:var(--accent)}
js
const stage=document.querySelector('.stage');let phase=0;function advance(){phase=(phase+1)%3;stage.dataset.phase=String(phase)}const timer=setInterval(advance,1200);stage.addEventListener('pointerdown',()=>{clearInterval(timer);advance()})

Kubernetes mutating admission policies use CEL rules to modify submitted resources inside the API server. They can cover common defaulting cases without an external webhook.

The demo adds a resource limit as a pod crosses the policy boundary. The feature is stable in Kubernetes 1.36, but matching scope and existing-field behavior still need review.

When to use

Use it to apply consistent defaults to submitted pod configurations.

Open as page ↗