問題文
A platform team must reject any Pod whose image comes from an untrusted registry. They evaluated the built-in ResourceQuota and PodSecurity admission controllers and found neither can express the rule. Which property of dynamic admission control makes Kyverno the right fit here?
選択肢
- Dynamic admission controllers are compiled into the API server binary, removing the network hop.
- Dynamic admission controllers run after the request has been persisted, so they can inspect the stored object.
- Dynamic admission controllers replace Kubernetes RBAC, so one rule set covers both authorization and validation.
- Dynamic admission controllers run custom decision logic supplied at runtime, so organization-specific rules can be expressed.