問題文
A platform team wants one validation rule reused with different numeric thresholds per team, without writing a separate rule for each team. In the cluster's built-in validating admission policy mechanism, which piece carries the per-team threshold?
選択肢
- The policy object itself, which lists every threshold as a separate expression and selects the right one with a condition that reads the namespace of the incoming object, since only the policy can contain expressions.
- A parameter resource, which the binding ties to the policy by name so that the same rule is evaluated against different values.
- A ConfigMap read by the policy at evaluation time through an external call, and the threshold would be fetched from outside the policy on every request that arrives.
- A separate binding per team with no parameter, since the binding provides scoping, so each team would end up maintaining its own copy of the whole rule expression.