Description
ImagePolicyWebhook is an admission plugin that lets an external backend decide whether images are allowed. Without a mechanism to enforce image policy, unapproved images may be deployed. Enabling this plugin alone does not verify signatures or vulnerabilities automatically; other admission controls can also enforce organizational policy.
Potential impact
- Unapproved images or code from untrusted sources may run.
- Inconsistent validation and exception handling can make supply-chain risks harder to control.
Remediation
- Define the required registry, signature and image-approval policies, and configure admission controls that actually validate them.
- For ImagePolicyWebhook, configure the plugin, required API enablement, AdmissionConfiguration and TLS backend connection together. Test whether requests are allowed when the backend fails, as well as normal approval and rejection outcomes.
Examples
These historical partial examples compare Kubernetes v1.30.0 arguments. Use a supported version and complete API server configuration. Configuration files, the TLS backend and required --runtime-config=imagepolicy.k8s.io/v1alpha1=true setting are omitted and must be supplied separately.
Before
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --enable-admission-plugins=AlwaysAdmit
AlwaysAdmit itself does not validate image policy. Also check other policy controls in the existing cluster.
After
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --enable-admission-plugins=ImagePolicyWebhook
- --admission-control-config-file=/etc/kubernetes/image-policy-webhook.yaml
The webhook plugin and configuration path are specified. Actual approval and rejection decisions require a policy backend and its connection configuration.