Description
The NamespaceLifecycle admission plugin controls actions such as creating resources in nonexistent or terminating namespaces. Disabling it can allow operations inconsistent with the namespace lifecycle. It is enabled by default and does not replace RBAC access controls.
Potential impact
- Adding resources to a terminating namespace can complicate cleanup.
- Inconsistent namespace and resource state can make recovery harder.
Remediation
- On a self-managed API server, remove NamespaceLifecycle from --disable-admission-plugins and retain its default enabled state. For managed services, check the provider’s control-plane policy.
- After applying the configuration, verify namespace creation and deletion and the expected acceptance or rejection of related requests. Manage user and service-account RBAC permissions separately.
Examples
These historical excerpts compare API server arguments for Kubernetes v1.30.0. Actual use needs a supported version and complete control-plane configuration.
Before
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --disable-admission-plugins=NamespaceLifecycle
NamespaceLifecycle is explicitly disabled.
After
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --enable-admission-plugins=NamespaceLifecycle
The disabling argument is removed and NamespaceLifecycle is explicitly enabled. Because this plugin is enabled by default, it need not always be listed explicitly unless other configuration disables it.