chainsaw admission
K8s admission webhook helpers (shadow-mode soak gate, etc)
K8s admission webhook helpers (shadow-mode soak gate, etc)
| Subcommand | What it does |
|---|---|
chainsaw admission soak | Shadow-mode soak gate (status / clear before flipping failurePolicy: Fail) |
chainsaw admission soak clear | Check the soak gate and print the kubectl patch if it passes |
chainsaw admission soak status | Report the shadow-mode soak window and would-block counts |
chainsaw admission [command]
Helpers for the K8s ValidatingAdmissionWebhook emitted by the hardening wizard (/admin/hardening).
The webhook ships in shadow mode (failurePolicy: Ignore) by default. Use
chainsaw admission soak status to see how much soak it has accumulated,
and chainsaw admission soak clear to check whether it’s safe to flip
to fail-closed (failurePolicy: Fail).
chainsaw admission soak
Shadow-mode soak gate (status / clear before flipping failurePolicy: Fail)
chainsaw admission soak [command]
chainsaw admission soak clear
Check the soak gate and print the kubectl patch if it passes
chainsaw admission soak clear [flags]
Run the soak gate. On pass, prints a single kubectl patch command
the operator should run to flip failurePolicy: Ignore → Fail. On fail,
prints which criterion failed and a suggested next step.
This command NEVER applies the patch itself. The flip-to-Fail action stays in the operator’s hands.
Exit codes: 0 gate cleared; kubectl patch printed to stdout 10 gate not cleared; conditions printed to stderr 2 HTTP / auth / unreachable
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--days | int | 0 | Soak window minimum in days (default server-side: 7) |
--json | bool | — | Output raw JSON |
--max-deny-rate | float64 | -1 | Maximum would-deny / total ratio (default server-side: 0.0) |
The global flags apply here too.
chainsaw admission soak status
Report the shadow-mode soak window and would-block counts
chainsaw admission soak status [flags]
Report soak progress for the K8s admission webhook in shadow mode.
Prints days observed, total admission requests seen, would-deny counts,
and the per-criterion gate verdict. Exit code is 0 even when the gate
is not yet cleared — use chainsaw admission soak clear for an
exit-code-based check.
Flags: –days INT minimum soak window (default 7) –max-deny-rate F ceiling for would-deny/total (default 0.0) –json emit raw JSON instead of a human table
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--days | int | 0 | Soak window minimum in days (default server-side: 7) |
--json | bool | — | Output raw JSON |
--max-deny-rate | float64 | -1 | Maximum would-deny / total ratio (default server-side: 0.0) |
The global flags apply here too.