Description
AlwaysAdmit does not reject requests or validate security policy itself. It does not bypass other admission plugins, but it provides no protection on its own. It has been deprecated since Kubernetes v1.13.
The Kubernetes API server is central to creating and modifying workloads. Enforce security requirements through admission plugins and policies that perform actual validation.
Potential impact
- Without other validating policies, inappropriate resource creation or modification may be allowed.
- Weak policy checks can let unsafe configuration reach the cluster.
- Operators may incorrectly assume that security validation is in place.
Remediation
- Remove
AlwaysAdmitfrom--enable-admission-plugins. - Preserve required default admission functions and configure policies such as Pod Security Admission to enforce the actual requirements.
- Periodically review API server arguments and static Pod manifests.
Examples
These API server excerpts remove an unnecessary plugin argument. Match the image to the actual cluster version. Other settings are omitted; removing the argument alone does not configure security policy.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--enable-admission-plugins=AlwaysAdmit"]
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: []
Explanation:
- Before:
AlwaysAdmitprovides no validation. Check whether other active policies enforce the required restrictions. - After: The unnecessary plugin is removed. Verify the effective default plugins and separate security policies.