Control plane
Webhooks
21 / 82

Mutating webhooks change the object; validating webhooks only say yes or no.

Service-mesh sidecar injection and policy engines such as Kyverno and Gatekeeper work through these hooks. Order matters, and so does failurePolicy.

API serverauthn + authz okMutating webhooksinject sidecar, add labelsmay MODIFY the objectValidating webhookspolicy enginesALLOW or DENY onlyPersisted in etcdthe final, mutated objectRejected: 403nothing is stored

Why mutate before validate?

Validation then sees the final object. A policy requiring a label is not wrongly failed by an object a later webhook would have fixed.

failurePolicy: Fail

Webhook unreachable means request rejected. Safe for security policy, but a dead webhook can block the whole cluster.

failurePolicy: Ignore

Webhook unreachable means request allowed. Good for convenience hooks, but policy silently stops.