Review Kubernetes NamespaceLifecycle admission settings

Keep the default control that prevents resource creation in inappropriate namespace states.

Description

The NamespaceLifecycle admission plugin controls actions such as creating resources in nonexistent or terminating namespaces. Disabling it can allow operations inconsistent with the namespace lifecycle. It is enabled by default and does not replace RBAC access controls.

Potential impact

  • Adding resources to a terminating namespace can complicate cleanup.
  • Inconsistent namespace and resource state can make recovery harder.

Remediation

  • On a self-managed API server, remove NamespaceLifecycle from --disable-admission-plugins and retain its default enabled state. For managed services, check the provider’s control-plane policy.
  • After applying the configuration, verify namespace creation and deletion and the expected acceptance or rejection of related requests. Manage user and service-account RBAC permissions separately.

Examples

These historical excerpts compare API server arguments for Kubernetes v1.30.0. Actual use needs a supported version and complete control-plane configuration.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --disable-admission-plugins=NamespaceLifecycle

NamespaceLifecycle is explicitly disabled.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --enable-admission-plugins=NamespaceLifecycle

The disabling argument is removed and NamespaceLifecycle is explicitly enabled. Because this plugin is enabled by default, it need not always be listed explicitly unless other configuration disables it.

References