<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>admission-control on Oleksandr Kulbida</title>
    <link>https://okulbida.com/tags/admission-control/</link>
    <description>Recent content in admission-control on Oleksandr Kulbida</description>
    <generator>Hugo -- gohugo.io</generator>
    <lastBuildDate>Wed, 09 Sep 2026 00:00:00 +0300</lastBuildDate><atom:link href="https://okulbida.com/tags/admission-control/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Kyverno threat model: the defaults that make enforcement optional</title>
      <link>https://okulbida.com/posts/kyverno-threat-model-hardening-guide/</link>
      <pubDate>Wed, 09 Sep 2026 00:00:00 +0300</pubDate>
      
      <guid>https://okulbida.com/posts/kyverno-threat-model-hardening-guide/</guid>
      <description>Fail open, by default Audit mode is not enforcement PolicyException: the quiet bypass Kyverno doesn&amp;rsquo;t watch its own namespace What Kyverno can never protect Sign and verify, not either Turning the admission controller into an SSRF probe Summary   Kyverno released a threat model and hardening guide in April 2026, produced by the security consultancy ControlPlane in partnership with the CNCF and reviewed by Kyverno&amp;rsquo;s own maintainers (Jim Bugwadia and Shuting Zhao among them).</description>
    </item>
    
  </channel>
</rss>
