A proposed four-day workshop on admission contracts
Participants need Kubernetes API knowledge and the ability to read a small request-handling implementation. We use a prepared example to investigate behavior, not a complete production webhook project.
Day 1
Admission and workload requirements
Explain the request path, mutation, validation, and the distinction between schema checks and webhook logic. Define the resource scope and result the example needs.
Hands-on exercises
- Compare valid, invalid, and excluded requests against a written contract.
- Identify behavior that can use built-in validation instead of another dependency.
Day 2
Configuration, repeated calls, and controller interactions
Connect webhook configuration and templated deployment resources to API processing. Examine repeated mutation and conflicts with other controllers.
Hands-on exercises
- Configure a narrowly scoped example and inspect its admitted output.
- Repeat an input and verify that the effect remains consistent.
Day 3
Backend connectivity and failure policy
Trace API-server access to the webhook, its Service, certificates, and dependencies. Compare an explicit denial with an inability to call the backend.
Hands-on exercises
- Introduce a timeout or trust failure and observe the selected failure policy.
- Verify that unrelated resources remain outside the webhook's scope.
Day 4
Recovery and maintainable operation
Review permissions, resource availability, certificate lifecycle, and staged rollout. Exercise the component's own failure and recovery path before accepting the configuration.
Hands-on exercises
- Confirm that the webhook does not block the resources needed for its recovery.
- Record behavioral checks and stop conditions for a future update.
Your admission rules, API questions, and component responsibilities can shape the agenda. Get in touch to tailor the workshop to your team's work.