M7 · Observability, cost and troubleshooting
Webhook failures
50 / 61

A failing admission webhook can block the entire API path

When creates or updates time out, identify the webhook, its failure policy and whether the API server can reach a ready endpoint.

1Read API errorCapture the webhook name and timeout or denial.
2Inspect configurationCheck rules, selectors, timeout and failurePolicy.
3Find endpointsConfirm the backing Service has ready endpoints.
4Test network and TLSValidate control-plane reachability and serving certificate.
5Recover safelyUse a reviewed break-glass change, then restore enforcement.
Never delete webhook configuration blindly; understand what protection it provides and how to restore it.