Admission Control Stops Bad Specs, Not Bad Runtime Behavior
Pod Security Admission, CEL policies, and admission webhooks can reject unsafe manifests before they land in etcd. They still do not tell you what a workload executed after startup, which is why platform teams should separate preventive policy from runtime evidence.
March 11, 2026