The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Professional · Module 4: DevSecOps and supply chain

Policy and Admission: Rejecting the Bad Before It Runs

Admission is the last checkpoint before the cluster believes something. Policies evaluated there reject unsigned artifacts, forbidden images and known-bad shapes with messages that teach, while audit mode previews new rules before they bite.

10 min reading

Objectives

  • Explain where admission sits: between intent and persistence
  • Write policies that name the rule, the reason and the fix in rejections
  • Require provenance and signed artifacts for chosen sources
  • Test policy changes like code: staging, canary, audit before enforce

Why this matters

An unsigned image from an unfamiliar registry deploys to production on a Friday because nothing stood between the manifest and the cluster. The postmortem finds the policy document that recommended signatures, filed and unenforced. Recommendations do not stop deploys; admission does. Every supply-chain control that matters ends as an evaluated rule at admission, or it ends as a suggestion the incident ignores.

Concepts

Admission evaluates requests before persistence: this image, this namespace, right now. Policies check provenance signatures, registry allow-lists, required labels, forbidden shapes (privileged, latest tags, unpinned digests). Rejections carry the rule, the reason and the fix; a developer who learns from the message complies next time, one who gets a bare denial routes around. The M17 policy lesson returns with supply-chain teeth.

Roll out policy like releases. Audit mode first: evaluate and log without rejecting, measure the blast radius against real traffic. Then warn, then enforce, namespace by namespace, with the violations dashboard proving readiness at each step. A policy flipped straight to enforce breaks Friday deploys and teaches the organization that policy is the enemy; staged rollout teaches that it is the guardrail.

Exemptions are records, not holes. Break-glass paths exist for incidents, with automatic expiry, mandatory review and full audit. An exemption without expiry is a permanent bypass wearing a temporary name. Review exemptions on schedule; each renewal needs a reason, or the bypass closes.

Worked example

A demo cluster admits signed fixture artifacts and rejects the unsigned with quoted rule-reason-fix messages. A new provenance requirement rolls out in audit mode: violations logged for a week, dashboard reviewed, then enforced with zero surprise breakages. The staged rollout is the deliverable as much as the rule.

Common wrong move

Enforcing untested policy on Friday afternoon. The rejections are correct and the timing is hostile; the organization learns to fear the checkpoint instead of trusting it. Audit, warn, enforce, on a Tuesday.

Quick check

An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.

Lesson feedback

No published feedback yet.

Log in and complete the lesson to leave feedback.

Exercise

Stage an unsigned artifact rejection with a teaching message on a local setup, then roll a new provenance rule through audit to enforce with the dashboard reviewed.

Pass criteria

The record shows the quoted rejection with rule, reason and fix, plus the audit log, dashboard review and clean enforcement.

Sources

Log in to track progressFree account: stores only your lesson progress and quiz results.