Skip to content

Intercepting resources in the kube-system namespace / GKE control plane impact #148

@yantsa

Description

@yantsa

Community Note

  • Please vote on this issue by adding a 👍 reaction
    to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do
    not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment.

Description

Installed using helm in a GKE 1.33 cluster . Google console UI started reporting this health warning

This cluster has an admission webhook installed that is intercepting system critical requests in the last 24 hours. Intercepting these requests can impact availability of the GKE Control Plane

Affected Webhooks

Name Reason
kube-startup-cpu-boost-mutating-webhook-configuration Intercepting resources in the kube-system namespace

which is quiet worrying .

References

Google docs about unsafe webhooks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions