Get the App
SLTechnology News&Howtos  ›  Servers  › 

How to analyze the use of built-in admission controller plug-in MutatingAdmissionWebhook

Shulou Source: shulou.com Published: 2022-05-31 18:15:21 10月03日 Update

Today, I will talk to you about how to analyze the use of the built-in access controller plug-in MutatingAdmissionWebhook, which may not be well understood by many people. in order to make you understand better, the editor has summarized the following for you. I hope you can get something according to this article.

MutatingAdmissionWebhook is an admission controller plug-in built into the system and enabled by default, which is called during the kube-apiserver Review request (Mutating admission) phase to review the request.

Unlike other prepare controller plug-ins, MutatingAdmissionWebhook itself does not directly review the request, but forwards the task to the corresponding webhook (multiple webhook serial calls), and if any of the webhook returns fails, the MutatingAdmissionWebhook immediately rejects the request. The relationship between MutatingAdmissionWebhook and webhook is shown in the following figure:

Webhook is usually a web service responsible for reviewing resource objects. Webhook is divided into two categories: Mutating (modified) and Validating (validated) according to whether the request will be modified. MutatingAdmissionWebhook is responsible for managing and invoking the webhook of type Mutating, which is registered with the system through the MutatingWebhookConfiguration object. The MutatingWebhookConfiguration object describes the service address of webhook, the type of resource object of concern, and other information. MutatingAdmissionWebhook fetches the webhook list based on the MutatingWebhookConfiguration object and filters and invokes webhook when the API request arrives. More information about the MutatingWebhookConfiguration object will be covered in later chapters.

MutatingAdmissionWebhook is an important extension mechanism of Kubernetes, which is often used to review and rewrite extended CRD (CustomResourceDefination) objects, but it can also be used for Kubernetes native resource objects, such as adding label automatically when Pod is created.

After reading the above, do you have any further understanding of how to analyze the use of the built-in admission controller plug-in MutatingAdmissionWebhook? If you want to know more knowledge or related content, please follow the industry information channel, thank you for your support.

Tags: Objects controllers plug-ins controls access content types resources analysis information more systems services different important tasks due addresses multiple mechanisms Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Huawei macOS Microsoft Shulou Technology MySQL