Kubernetes Admission Control: Image Signing & Policy Gate (2D)
Interactive 2D Kubernetes admission-controller simulator: container images travel along a conveyor toward a validating webhook that checks signature, privilege, resource limits and CVE count — toggle policies, drag to pan and scroll to zoom, and watch which images get admitted or rejected in real time.
Container images roll along a conveyor toward a validating admission webhook, each one carrying randomised real-world attributes — a signature status, a CVE count from an image scan, a privileged-mode flag and whether resource limits are set. Toggle the same policies a cluster operator would configure in OPA Gatekeeper or Kyverno — require signed images, block privileged pods, require resource limits, and cap the allowed CVE count — and watch the gate admit or reject each image live, scheduling the winners onto an instanced worker-node grid while rejects fall away and fade. Drag to pan the view and scroll to zoom in on the belt or the cluster. Live counters track admitted, rejected and the running admission rate, and the "How it works" panel spells out the AND-of-constraints logic every real admission controller implements.
2D companion to the 3D admission-controller pipeline: container images travel along a top-down conveyor toward a validating webhook that checks signature, privilege, resource limits and CVE count, with the same AND-of-constraints admission logic rendered as flat canvas shapes you can pan and zoom instead of a 3D scene.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install