An admission controller webhook for Kubernetes based on Open Policy Agent, which Azure Policy for Kubernetes builds on. Running a separately installed copy alongside the add-on is unsupported.
Also called OPA Gatekeeper.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Gatekeeper in context, with comparison tables and the common traps.
Terms in this definition
- Webhook
In an action group, an action that posts the alert payload to an HTTP endpoint; each subscription may make up to 1,500 such calls per minute.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
- Azure Policy for Kubernetes
Admission control for Kubernetes based on Gatekeeper v3, installed as an AKS add-on or, on other clusters, an Arc extension. It acts as a webhook so that non-compliant pods are rejected by Azure Policy definitions set to Deny.
Related terms
- EnforceOPAConstraint
Retired Azure Policy effect for Kubernetes, alongside EnforceRegoPolicy, that enforced Open Policy Agent Gatekeeper constraints. Azure Policy for Kubernetes now uses Audit and Deny instead.