Admission Policy Audit Mode
ClosePart of Admission Control.
- What it is
- Policies run in audit mode in non-production environments so violations are recorded and understood before enforcement is switched on.
- Why it matters
- Switching a new policy straight to blocking in production breaks deployments, and the usual reaction is to switch the policy off for good.
- You have it when
- The same policies run in non-production recording what they would have refused, and that record is reviewed before enforcement is turned on.
What is wrong
No remediation deadline — expected a remediation deadline, actual none
The thing in place is Kyverno policies in audit mode.
Required as recommended: Required by profile rule(s): KUBERNETES_WORKLOAD_SECURITY
Every scope this job would settle
| Environment | Technology | Phase | Control point | Weight |
|---|
| Production | Kubernetes | Deploy | Admission | 1 |
Something you already own
Nothing you already run claims to do this job.
See the whole capabilityChange an answer