0Pricing
Docker & Kubernetes for Developers · 강의

Admission 웹훅으로 API 서버 확장하기

검증 및 변경 admission 웹훅을 사용해 Kubernetes API 요청을 처리 중간에 가로채고 검증하거나 변경하여 클러스터 정책을 적용해 보세요.

Admission 웹훅으로 API 서버 확장하기은(는) CoddyKit의 무료 Docker & Kubernetes for Developers 강의입니다. 이것은 4개 중 4번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Docker & Kubernetes for Developers 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Docker & Kubernetes for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

What Is Admission Control

After authentication and authorization, requests pass through admission controllers that can validate or modify objects before they are persisted.

Two Kinds of Webhooks

Dynamic admission uses webhooks: mutating webhooks change objects, and validating webhooks accept or reject them.

Where They Sit in the Pipeline

The API server runs mutating webhooks first, then validating webhooks, so a mutation can add defaults before validation checks the final object.

A Use Case

Examples: inject a sidecar (mutating), enforce that every Pod sets resource limits (validating), or block images from untrusted registries.

The MutatingWebhookConfiguration

This resource registers your webhook endpoint with the API server.

apiVersion: admissionregistration.k8s.io/v1
kind: MutatingWebhookConfiguration
metadata:
  name: add-defaults
webhooks:
  - name: defaults.example.com
    clientConfig:
      service:
        name: webhook-svc
        namespace: default
        path: /mutate
      caBundle: <base64-ca>
    rules:
      - operations: ["CREATE"]
        apiGroups: [""]
        apiVersions: ["v1"]
        resources: ["pods"]

The AdmissionReview Payload

The API server sends an AdmissionReview JSON to your webhook and expects an AdmissionReview response with allowed true/false, and for mutation a JSONPatch.

Returning a JSON Patch

A mutating webhook returns a base64-encoded JSONPatch describing the changes to apply.

{"response":{"allowed":true,"patchType":"JSONPatch","patch":"<base64-patch>"}}

failurePolicy Matters

failurePolicy: Fail blocks requests if the webhook is down, which is safe but can lock up the cluster; Ignore lets requests through, which is risky for security policies.

Scoping With Selectors

Use namespaceSelector and objectSelector to limit which requests hit your webhook, avoiding overhead and accidental scope creep.

Policy Engines as an Alternative

Instead of writing webhook servers, tools like OPA Gatekeeper and Kyverno provide declarative policies on top of the same admission mechanism.

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: require-limits
spec:
  validationFailureAction: Enforce
  rules:
    - name: check-limits
      match:
        any:
          - resources:
              kinds: [Pod]
      validate:
        message: "CPU and memory limits are required"
        pattern:
          spec:
            containers:
              - resources:
                  limits:
                    memory: "?*"

TLS Is Required

Webhook endpoints must serve HTTPS with a certificate trusted via the caBundle, since the API server only calls webhooks over TLS.

Quick Check

Test what you have learned.

Recap

You learned how admission webhooks extend the API server: mutating webhooks change objects and validating webhooks enforce policy, the AdmissionReview flow, failurePolicy and selectors, TLS requirements, and policy engines like Kyverno and Gatekeeper.

자주 묻는 질문

“Admission 웹훅으로 API 서버 확장하기” 강의는 무료인가요?

네 — “Admission 웹훅으로 API 서버 확장하기” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Docker & Kubernetes for Developers 강의 전체를 잠금 해제할 수 있습니다. Docker & Kubernetes for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.

“Admission 웹훅으로 API 서버 확장하기”에서 뭘 배우나요?

검증 및 변경 admission 웹훅을 사용해 Kubernetes API 요청을 처리 중간에 가로채고 검증하거나 변경하여 클러스터 정책을 적용해 보세요. 브라우저에서 직접 실행하는 실습 코드로 Docker & Kubernetes for Developers을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Docker & Kubernetes for Developers을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Docker & Kubernetes for Developers은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 4번째 강의입니다.

“Admission 웹훅으로 API 서버 확장하기” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Docker & Kubernetes for Developers 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Docker & Kubernetes for Developers 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 사용자 지정 리소스 정의(CRD)
  2. Kubernetes의 오퍼레이터 패턴
  3. Kubernetes를 활용한 서버리스(Knative)
  4. Admission 웹훅으로 API 서버 확장하기
← Docker & Kubernetes for Developers(으)로 돌아가기