Admission control for Kubernetes based on Gatekeeper v3, installed as an AKS add-on or, on other clusters, an Arc extension. It acts as a webhook so that non-compliant pods are rejected by Azure Policy definitions set to Deny.
Also called Azure Policy add-on for AKS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Policy for Kubernetes in context, with comparison tables and the common traps.
Terms in this definition
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- Gatekeeper
An admission controller webhook for Kubernetes based on Open Policy Agent, which Azure Policy for Kubernetes builds on. Running a separately installed copy alongside the add-on is unsupported.
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Actions Runner Controller
A Kubernetes operator maintained by GitHub and deployed with Helm. It manages and automatically scales self-hosted GitHub Actions runners inside your own clusters.
- Webhook
In an action group, an action that posts the alert payload to an HTTP endpoint; each subscription may make up to 1,500 such calls per minute.
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
Related terms
- EnforceOPAConstraint
Retired Azure Policy effect for Kubernetes, alongside EnforceRegoPolicy, that enforced Open Policy Agent Gatekeeper constraints. Azure Policy for Kubernetes now uses Audit and Deny instead.