TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #1576 394

Forwarded from KubeFM

Gordon Myers explains why thorough testing is critical when implementing webhooks in Kubernetes.

He shares a real-world example of building a Mutating Webhook that injects secrets from HashiCorp Vault into running applications using pod annotations. The discussion covers:

- How a 500 error in webhooks can prevent pods from launching entirely
- The implementation of a custom entry point script for injecting secrets as environment variables
- Why webhooks require extensive unit testing due to their cluster-wide impact

The example demonstrates how seemingly simple webhook implementations can have significant consequences for the entire Kubernetes cluster if not properly tested.

Watch the full episode: https://ku.bz/Dmn93dd7M
More from @kubesploit
  1. Sep 28, 2026This article follows a secret from an external store into a pod through the Secrets Store…
  2. Sep 28, 2026Heading to KubeCon + CloudNativeCon North America? Join us the day before for our first in…
  3. Sep 25, 2026This tutorial builds a Docker image with a secret, then shows how it still sits in an earl…
  4. Sep 24, 2026This article explains how Vault piles up unexpired leases when pods keep re-authenticating…
  5. Sep 23, 2026This article asks what a container can block on its own when a dependency turns malicious,…
  6. Sep 23, 2026This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →