Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “admission control”
10 publicationsPlan the move from ingress-nginx to Gateway API
Ingress-nginx is archived and will not be patched again. Contain the old controller, inventory the behaviors your clients depend on, and cut over to Gateway API with evidence and a rollback path.
Workload security · Kubernetes / Google Cloud / AWS / Azure · By Cloud Security DeskPlan for the backlog that follows a regional cloud outage
AWS fixed the DNS fault behind its October 2025 us-east-1 outage within three hours, yet recovery ran into the afternoon. Design retries, queues and capacity automation for that second phase.
Resilience · Amazon Web Services · By Cloud Security DeskCount tokens before sending a prompt to Amazon Bedrock
Count a Bedrock prompt for the chosen model, check endpoint support, distinguish context and output limits, and verify usage without logging prompts.
AI systems · AWS · By Cloud Security DeskIsolate document parsing before RAG ingestion
Give document parsing a bounded worker, then admit its extracted content separately before embedding or indexing.
AI systems · Apache Tika / Kubernetes / gVisor · By Cloud Security DeskGive Kubernetes admission webhooks an explicit failure contract
Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.
Workload security · Kubernetes · By Cloud Security DeskChoosing isolation for a Kubernetes tenant
A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.
Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security DeskWhere fine tuning data needs a trust boundary
A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.
AI systems · By Cloud Security DeskError budgets for controlled service degradation
Protect essential work under load while counting rejected and degraded requests against the service promise that users were actually given.
Resilience · Google / Envoy · By Cloud Security DeskStop retries from amplifying an outage
Count attempts across the complete request path, give retries a finite owner and budget, and define how repeated intent avoids duplicate side effects.
Resilience · AWS · By Cloud Security DeskVerify container provenance before admitting a pinned image
Use the digest to identify the artifact, then check who signed it, which builder produced it, and which evidence survived promotion into the deployment registry.
Workload security · Kubernetes / Docker / Sigstore · By Cloud Security Desk