Best practices

K8S API server configuration without NamespaceLifecycle admissions control plugin

Risk Level

Informational (4)

Platform(s)
  • N/A

Compliance Frameworks

Description

It was found that the API server configuration admission control plugins parameter does not include 'NamespaceLifecycle'. An admission controller is a code which being executed after the request authentication and authorization in order to validate it or change it. This admission controller ensures that a request in an invalid namespace will be rejected.
  • Recommended Mitigation

    It is recommended to include the NamespaceLifecycle plugin in the '--enable-admission-plugins' parameter.