Learn about validating Kubernetes webhook controllers in this 23-minute conference talk from OpenSSF. Explore a framework for end-users to independently validate and interrogate controller behaviors in their environments, particularly focusing on how these behaviors satisfy regulated standards and best practices. Discover how to use the open-source tool Lula to add cluster resources, measure controller responses, and generate behavioral validations. Understand the importance of continuous monitoring and evaluation of webhook controllers performing critical security functions, especially as systems evolve and environments scale. Master the implementation of repeatable and scalable evaluation methods for admission and mutation controllers, moving beyond standard unit and end-to-end testing to ensure robust security validation in complex Kubernetes environments.
Validating Kubernetes Webhook Controllers - A Framework for Testing and Monitoring