You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Multiplesources confirm anecdotally that the Kubernetes admission webhook requests are processed serially in lexicographical order. Given that Kyverno is a policy enforcement solution, it should be able to be configure as close as possible to the beginning of this pipeline.
Solution Description
*WebhookConfiguration names currently appeared hard coded here. Solution should support overriding these via runtime configuration (environment variables, command arguments, etc.) that can also be configured through Helm Chart values.
Alternatives
No response
Additional Context
I am trying to label Pods with a Kyverno policy for service mesh proxy injection by Istio but Istio's MutatingWebhookConfiguration responsible for injecting said Pods is lexicographically "lower" (comes before) Kyverno's:
I have searched other issues in this repository and mine is not recorded.
The text was updated successfully, but these errors were encountered:
iAnomaly
added
enhancement
New feature or request
triage
Default label assigned to all new issues indicating label curation is needed to fully organize.
labels
Aug 9, 2023
Thanks for opening your first issue here! Be sure to follow the issue template!
chipzoller
added
webhook
and removed
triage
Default label assigned to all new issues indicating label curation is needed to fully organize.
labels
Aug 10, 2023
@chipzoller: Initial attempt at resolving this issue in #8059. How do you feel about applying the same prefix to all mutating webhooks for consistency even if the resource mutating webhook is the only one that would benefit functionally?
Problem Statement
Multiple sources confirm anecdotally that the Kubernetes admission webhook requests are processed serially in lexicographical order. Given that Kyverno is a policy enforcement solution, it should be able to be configure as close as possible to the beginning of this pipeline.
Solution Description
*WebhookConfiguration names currently appeared hard coded here. Solution should support overriding these via runtime configuration (environment variables, command arguments, etc.) that can also be configured through Helm Chart values.
Alternatives
No response
Additional Context
I am trying to label Pods with a Kyverno policy for service mesh proxy injection by Istio but Istio's MutatingWebhookConfiguration responsible for injecting said Pods is lexicographically "lower" (comes before) Kyverno's:
Slack discussion
https://kubernetes.slack.com/archives/CLGR9BJU9/p1691624820592279
Research
The text was updated successfully, but these errors were encountered: