DevOps Professional · Module 4: DevSecOps and supply chain
Policy and Admission: Rejecting the Bad Before It Runs
Admission is the last checkpoint before the cluster believes something. Policies evaluated there reject unsigned artifacts, forbidden images and known-bad shapes with messages that teach, while audit mode previews new rules before they bite.
10 min reading
Objectives
- Explain where admission sits: between intent and persistence
- Write policies that name the rule, the reason and the fix in rejections
- Require provenance and signed artifacts for chosen sources
- Test policy changes like code: staging, canary, audit before enforce
Why this matters
An unsigned image from an unfamiliar registry deploys to production on a Friday because nothing stood between the manifest and the cluster. The postmortem finds the policy document that recommended signatures, filed and unenforced. Recommendations do not stop deploys; admission does. Every supply-chain control that matters ends as an evaluated rule at admission, or it ends as a suggestion the incident ignores.
Concepts
Admission evaluates requests before persistence: this image, this namespace, right now. Policies check provenance signatures, registry allow-lists, required labels, forbidden shapes (privileged, latest tags, unpinned digests). Rejections carry the rule, the reason and the fix; a developer who learns from the message complies next time, one who gets a bare denial routes around. The M17 policy lesson returns with supply-chain teeth.
Roll out policy like releases. Audit mode first: evaluate and log without rejecting, measure the blast radius against real traffic. Then warn, then enforce, namespace by namespace, with the violations dashboard proving readiness at each step. A policy flipped straight to enforce breaks Friday deploys and teaches the organization that policy is the enemy; staged rollout teaches that it is the guardrail.
Exemptions are records, not holes. Break-glass paths exist for incidents, with automatic expiry, mandatory review and full audit. An exemption without expiry is a permanent bypass wearing a temporary name. Review exemptions on schedule; each renewal needs a reason, or the bypass closes.
Worked example
A demo cluster admits signed fixture artifacts and rejects the unsigned with quoted rule-reason-fix messages. A new provenance requirement rolls out in audit mode: violations logged for a week, dashboard reviewed, then enforced with zero surprise breakages. The staged rollout is the deliverable as much as the rule.
Common wrong move
Enforcing untested policy on Friday afternoon. The rejections are correct and the timing is hostile; the organization learns to fear the checkpoint instead of trusting it. Audit, warn, enforce, on a Tuesday.
Quick check
An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Lesson feedback
No published feedback yet.
Log in and complete the lesson to leave feedback.
Exercise
Stage an unsigned artifact rejection with a teaching message on a local setup, then roll a new provenance rule through audit to enforce with the dashboard reviewed.
Pass criteria
The record shows the quoted rejection with rule, reason and fix, plus the audit log, dashboard review and clean enforcement.