Courseiva
Supply Chain SecurityhardMultiple ChoiceObjective-mapped

Admission Controller Order: Why Mutating Webhooks Run Before Validating

A cluster has both ImagePolicyWebhook and a mutating webhook that adds a sidecar. The admin notices that even when ImagePolicyWebhook rejects an image, the mutating webhook has already added the sidecar. What admission ordering issue is occurring?

⚠ Common exam trap

The trap is that candidates think they can reorder admission controllers, but Kubernetes enforces a fixed order: mutating runs before validating. Therefore, placing a validating controller before a mutating one is not possible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Validating webhooks should run before mutating webhooks

In Kubernetes, admission controllers are invoked in a fixed order: mutating admission controllers (including MutatingAdmissionWebhook) run before validating ones (including ImagePolicyWebhook and ValidatingAdmissionWebhook). Therefore, the mutating webhook that adds the sidecar runs before ImagePolicyWebhook validates the image. This means even if ImagePolicyWebhook rejects the image, the sidecar has already been added. The issue is that validating webhooks should run before mutating webhooks to prevent such problems, but the fixed order prevents this. Option B is wrong because using a validating webhook still runs after mutating webhooks. Option C is a workaround but not related to the ordering issue. Option D is incorrect because you cannot change the order of built-in admission controllers; the order is fixed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Validating webhooks should run before mutating webhooks

    Why this is correct

    Correct. This describes the issue exactly: validating webhooks should run before mutating webhooks, but the fixed order causes them to run after, leading to the sidecar being added even when the image is rejected.

  • Use a validating webhook instead of ImagePolicyWebhook

    Why it's wrong here

    Wrong. Substituting ImagePolicyWebhook with a validating webhook does not change the order; mutating webhooks still run first.

  • The mutating webhook should be configured to skip pods with certain images

    Why it's wrong here

    Wrong. Configuring the mutating webhook to skip certain images is a potential workaround but does not address the fundamental ordering issue.

  • The ImagePolicyWebhook should be placed before the mutating webhook in the webhook configuration

    Why it's wrong here

    Wrong. In Kubernetes, the order of admission controllers is fixed: mutating controllers run before validating ones. You cannot reorder ImagePolicyWebhook before the mutating webhook in the plugin chain.

About these practice questions

One of 114 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE of the following are correct statements about Kubernetes admission controllers in the context of supply chain security? (Select 3)

hard
  • A.Admission controllers are executed in a specific order that can affect the final state of the resource
  • B.ValidatingAdmissionWebhook can be used to enforce policies like requiring all images to be signed
  • C.MutatingAdmissionWebhook can only modify pods, not other resources
  • D.ImagePolicyWebhook is used to validate container images against an external policy
  • E.OPA/Gatekeeper uses MutatingAdmissionWebhook to enforce policies

Why A: Admission controllers are executed in a specific order: mutating controllers run first, then validating controllers. This ordering is critical because a mutating webhook can modify the resource before a validating webhook evaluates it, potentially bypassing intended policies if the order is not carefully managed. The Kubernetes API server processes admission controllers sequentially based on the order defined in the API server flags or the built-in chain, which directly affects the final resource state.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.