chainsaw admission

K8s admission webhook helpers (shadow-mode soak gate, etc)

K8s admission webhook helpers (shadow-mode soak gate, etc)

SubcommandWhat it does
chainsaw admission soakShadow-mode soak gate (status / clear before flipping failurePolicy: Fail)
    chainsaw admission soak clearCheck the soak gate and print the kubectl patch if it passes
    chainsaw admission soak statusReport the shadow-mode soak window and would-block counts
chainsaw admission [command]

Helpers for the K8s ValidatingAdmissionWebhook emitted by the hardening wizard (/admin/hardening).

The webhook ships in shadow mode (failurePolicy: Ignore) by default. Use chainsaw admission soak status to see how much soak it has accumulated, and chainsaw admission soak clear to check whether it’s safe to flip to fail-closed (failurePolicy: Fail).

chainsaw admission soak

Shadow-mode soak gate (status / clear before flipping failurePolicy: Fail)

chainsaw admission soak [command]

chainsaw admission soak clear

Check the soak gate and print the kubectl patch if it passes

chainsaw admission soak clear [flags]

Run the soak gate. On pass, prints a single kubectl patch command the operator should run to flip failurePolicy: Ignore → Fail. On fail, prints which criterion failed and a suggested next step.

This command NEVER applies the patch itself. The flip-to-Fail action stays in the operator’s hands.

Exit codes: 0 gate cleared; kubectl patch printed to stdout 10 gate not cleared; conditions printed to stderr 2 HTTP / auth / unreachable

Flags
FlagTypeDefaultDescription
--daysint0Soak window minimum in days (default server-side: 7)
--jsonbool—Output raw JSON
--max-deny-ratefloat64-1Maximum would-deny / total ratio (default server-side: 0.0)

The global flags apply here too.

chainsaw admission soak status

Report the shadow-mode soak window and would-block counts

chainsaw admission soak status [flags]

Report soak progress for the K8s admission webhook in shadow mode.

Prints days observed, total admission requests seen, would-deny counts, and the per-criterion gate verdict. Exit code is 0 even when the gate is not yet cleared — use chainsaw admission soak clear for an exit-code-based check.

Flags: –days INT minimum soak window (default 7) –max-deny-rate F ceiling for would-deny/total (default 0.0) –json emit raw JSON instead of a human table

Flags
FlagTypeDefaultDescription
--daysint0Soak window minimum in days (default server-side: 7)
--jsonbool—Output raw JSON
--max-deny-ratefloat64-1Maximum would-deny / total ratio (default server-side: 0.0)

The global flags apply here too.