Kubernetes v1.36 introduces manifest-based admission control to enforce security policies during cluster bootstrap and protect against unauthorized deletion. By loading admission policies directly from local files via the API server's configuration, this approach ensures critical security rules are active before the API server serves any requests.
Key points
Manifest-based admission control allows defining policies as disk-based YAML files, ensuring they are active from the moment the API server starts.
Static manifests mitigate the chicken-and-egg problem during cluster recovery and bootstrap by bypassing the API-based object creation cycle.
Objects defined as static manifests must use the reserved .static.k8s.io suffix to prevent naming collisions with standard API resources.
Static policies cannot be removed via standard API calls, preventing privileged users from disabling security controls via configuration deletion.