Slide 8
Slide 8 text
Kubernetes ΫϥελʹϙϦγʔΛద༻͢ΔͨΊͷओཁͳػೳ
▶ Built-in API Objects
+ Network Policy, RBAC, ResourceQuota ͳͲ
▶ Admission Controls
+ ϓϥάΠϯͱͯ͠ DefaultIngressClass, LimitRanger ͳͲ
+ Pod Security Standard ͷެ࣮ࣜͰ͋Δ Pod Security Admission ϓϥάΠϯͷ1ͭ
▶ Dynamic Admission ControlsʢValidating / Mutating Admission Webhookʣ
+ API Server ͕ड͚ͨϦΫΤετΦϒδΣΫτͷ੍ޚΛ֎෦αʔϏεͰߦ͑Δػೳ
+ ࣮ྫͱͯ͠ Kyverno, OPA / Gatekeeper ͳͲ
▶ Validating Admission Policyʢv1.29 ࣌ͰσϑΥϧτແޮͷ Beta ػೳʣ
+ Common Expression Language (CEL) ͰҙͷϙϦγʔΛఆٛͰ͖Δػೳ
+ CEL ࣮ߦͱҠ২ੑ͕ߴ͍͜ͱ͕ಛͷݴޠ
+ Validating Admission Webhook ͷସػೳ
+ API Server Ͱॲཧ͕݁͢ΔͨΊརେ͖͍