Admission Controller Order: Why Mutating Webhooks Run Before Validating
A cluster has both ImagePolicyWebhook and a mutating webhook that adds a sidecar. The admin notices that even when ImagePolicyWebhook rejects an image, the mutating webhook has already added the sidecar. What admission ordering issue is occurring?
⚠ Common exam trap
The trap is that candidates think they can reorder admission controllers, but Kubernetes enforces a fixed order: mutating runs before validating. Therefore, placing a validating controller before a mutating one is not possible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validating webhooks should run before mutating webhooks
In Kubernetes, admission controllers are invoked in a fixed order: mutating admission controllers (including MutatingAdmissionWebhook) run before validating ones (including ImagePolicyWebhook and ValidatingAdmissionWebhook). Therefore, the mutating webhook that adds the sidecar runs before ImagePolicyWebhook validates the image. This means even if ImagePolicyWebhook rejects the image, the sidecar has already been added. The issue is that validating webhooks should run before mutating webhooks to prevent such problems, but the fixed order prevents this. Option B is wrong because using a validating webhook still runs after mutating webhooks. Option C is a workaround but not related to the ordering issue. Option D is incorrect because you cannot change the order of built-in admission controllers; the order is fixed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Validating webhooks should run before mutating webhooks
Why this is correct
Correct. This describes the issue exactly: validating webhooks should run before mutating webhooks, but the fixed order causes them to run after, leading to the sidecar being added even when the image is rejected.
- ✗
Use a validating webhook instead of ImagePolicyWebhook
Why it's wrong here
Wrong. Substituting ImagePolicyWebhook with a validating webhook does not change the order; mutating webhooks still run first.
- ✗
The mutating webhook should be configured to skip pods with certain images
Why it's wrong here
Wrong. Configuring the mutating webhook to skip certain images is a potential workaround but does not address the fundamental ordering issue.
- ✗
The ImagePolicyWebhook should be placed before the mutating webhook in the webhook configuration
Why it's wrong here
Wrong. In Kubernetes, the order of admission controllers is fixed: mutating controllers run before validating ones. You cannot reorder ImagePolicyWebhook before the mutating webhook in the plugin chain.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
About these practice questions
One of 114 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are correct statements about Kubernetes admission controllers in the context of supply chain security? (Select 3)
hard- ✓ A.Admission controllers are executed in a specific order that can affect the final state of the resource
- ✓ B.ValidatingAdmissionWebhook can be used to enforce policies like requiring all images to be signed
- C.MutatingAdmissionWebhook can only modify pods, not other resources
- ✓ D.ImagePolicyWebhook is used to validate container images against an external policy
- E.OPA/Gatekeeper uses MutatingAdmissionWebhook to enforce policies
Why A: Admission controllers are executed in a specific order: mutating controllers run first, then validating controllers. This ordering is critical because a mutating webhook can modify the resource before a validating webhook evaluates it, potentially bypassing intended policies if the order is not carefully managed. The Kubernetes API server processes admission controllers sequentially based on the order defined in the API server flags or the built-in chain, which directly affects the final resource state.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.