Home▸Cybersecurity▸Kubernetes Admission Control: Image Signing & Policy Gate (2D)

Kubernetes Admission Control: Image Signing & Policy Gate (2D)

Interactive 2D Kubernetes admission-controller simulator: container images travel along a conveyor toward a validating webhook that checks signature, privilege, resource limits and CVE count — toggle policies, drag to pan and scroll to zoom, and watch which images get admitted or rejected in real time.

Cybersecurity2DAdvanced60 FPS📱 Mobile-adapted⇄ 3D version
2d-kubernetes-security-basics ↗ Open standalone

Container images roll along a conveyor toward a validating admission webhook, each one carrying randomised real-world attributes — a signature status, a CVE count from an image scan, a privileged-mode flag and whether resource limits are set. Toggle the same policies a cluster operator would configure in OPA Gatekeeper or Kyverno — require signed images, block privileged pods, require resource limits, and cap the allowed CVE count — and watch the gate admit or reject each image live, scheduling the winners onto an instanced worker-node grid while rejects fall away and fade. Drag to pan the view and scroll to zoom in on the belt or the cluster. Live counters track admitted, rejected and the running admission rate, and the "How it works" panel spells out the AND-of-constraints logic every real admission controller implements.

⚙ Under the hood

2D companion to the 3D admission-controller pipeline: container images travel along a top-down conveyor toward a validating webhook that checks signature, privilege, resource limits and CVE count, with the same AND-of-constraints admission logic rendered as flat canvas shapes you can pan and zoom instead of a 3D scene.

kubernetesadmission-controlcybersecuritydevsecopsopa-gatekeepercontainer-security2d-simulation

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)