Q: What is a mutating admission webhook and give a practical use case?
Admission webhooks intercept API requests before they're stored in etcd. Mutating webhooks can modify the request (add/change fields). Va...
#Kubernetes #Advanced Scenarios #L3 #Container Orchestration #K8s #etcd
🎙️ Candidate Opening & Architectural Context
""When troubleshooting Kubernetes, I always follow a structured layered model: Pod status -> Events -> Logs -> Network. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Admission webhooks intercept API requests before they're stored in etcd. Mutating webhooks can modify the request (add/change fields). Validating webhooks can accept or reject it.
- Istio/Linkerd sidecar injection — automatically inject the sidecar proxy container into every pod in labeled namespaces.
- Default resource limits — if a pod has no resource limits, auto-add safe defaults.
- Label injection — add team/cost-center labels to all pods.
2️⃣
Remediation & Permanent Safeguards
Practical use cases for mutating webhooks: The webhook is an HTTPS server (usually running as a pod). Kubernetes sends the resource spec to it, the server returns a JSON Patch with modifications. --- Q71-Q100. Rapid-fire Kubernetes Scenarios
- Image tag enforcement — replace
latesttag with the actual SHA digest.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Istio/Linkerd sidecar injection — automatically inject the sidecar proxy container into every pod in labeled namespaces.."
⚡ 60-Second Elevator Pitch Talking Points
- Istio/Linkerd sidecar injection — automatically inject the sidecar proxy container into every pod...
- Default resource limits — if a pod has no resource limits, auto-add safe defaults.
- Label injection — add team/cost-center labels to all pods.
Advertisement