Admission Control

by grafana1ccacf29049fApache-2.0279 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app. Provides guidance on implementing validation and mutation admission handlers for grafana-app-sdk apps.

AI-generated overview

Guides implementing validation and mutation admission handlers for grafana-app-sdk apps.

What it does
This skill provides guidance and code patterns for writing admission control handlers in grafana-app-sdk applications. It covers the Validator and Mutator interfaces, example implementations, handler registration in the app builder, admission request fields, and common validation patterns such as immutability and cross-field checks. It also explains how admission runs differently for standalone operators versus grafana/apps deployments.
When to use it
Use it when a user asks to write a validator, add validation, implement admission control, write a mutating webhook, or validate or mutate resources before they are persisted in a grafana-app-sdk app. It is aimed at developers working with grafana-app-sdk kinds and admission logic.
Requirements
Requires a grafana-app-sdk Go project; the skill is instructions only and ships no scripts. It references the grafana-app-sdk Go packages and the grafana-app-sdk CLI for generating an operator stub, and mentions Kubernetes admission webhooks and CUE kind definitions.

Admission Control

Admission control intercepts resource create/update requests before they are persisted. In grafana-app-sdk there are two types:

  • Validation — accept or reject a request; cannot modify the resource
  • Mutation — modify the resource before it is persisted (e.g. set defaults, normalize fields)

The app business logic for admission is identical whether the app runs as a standalone operator or inside grafana/apps. The only difference is the runtime: standalone apps stand up their own webhook server; grafana/apps apps have admission auto-registered as a Kubernetes plugin.

Getting Stubs

For standalone apps, if pkg/app/app.go does not yet exist, a stub App can be generated with:

bash
grafana-app-sdk project component add operator

This creates scaffolded simple.App which admission handlers can be added to for each kind in ManagedKinds.

Validator Interface

go
// Implement this interface for each kind you want to validatetype Validator interface {    Validate(ctx context.Context, request *app.AdmissionRequest) error}
  • Return nil to admit the request
  • Return an error to reject it (the error message is returned to the API caller)
  • app.AdmissionRequest provides access to the incoming object and operation type
  • You can use k8s.NewAdmissionError(err error, statusCode int, reason string) (from "github.com/grafana/grafana-app-sdk/k8s") to better control the returned error information

Validator Example

go
type MyKindValidator struct{}
func (v *MyKindValidator) Validate(ctx context.Context, req *app.AdmissionRequest) error {    obj, ok := req.Object.(*v1.MyKind)    if !ok {        return fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)    }
    // Validate spec fields    if obj.Spec.Title == "" {        return fmt.Errorf("spec.title is required")    }
    if obj.Spec.Count < 0 {        return fmt.Errorf("spec.count must be non-negative, got %d", obj.Spec.Count)    }
    // Distinguish create vs update    if req.Action == resource.AdmissionActionUpdate && req.OldObject != nil {        old, ok := req.OldObject.(*v1.MyKind)        if !ok {            return fmt.Errorf("admission request old object was of invalid type %T (expected *v1.MyKind)", req.OldObject)        }        if old.Spec.Title != obj.Spec.Title {            return fmt.Errorf("spec.title is immutable after creation")        }    }
    return nil}

Mutating Admission (Mutator)

go
// Implement this interface to mutate resources before persistencetype Mutator interface {    Mutate(ctx context.Context, request *app.AdmissionRequest) (*app.MutatingResponse, error)}
  • Return a MutatingResponse containing the (optionally modified) object
  • Return an error to reject the request entirely
  • Best practice is to reject requests from validators, not mutators

Mutating Handler Example

go
type MyKindMutator struct{}
func (m *MyKindMutator) Mutate(    ctx context.Context,    req *app.AdmissionRequest,) (*app.MutatingResponse, error) {    obj, ok := req.Object.(*v1.MyKind)    if !ok {        return nil, fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)    }
    // Set defaults on create    if req.Action == resource.AdmissionActionCreate {        if obj.Spec.Description == "" {            obj.Spec.Description = "No description provided"        }    }
    return &app.MutatingResponse{UpdatedObject: obj}, nil}

Registering Admission Handlers

Register validators and mutators when building the app in pkg/app/app.go:

go
func New(cfg app.Config) (app.App, error) {    cfg.KubeConfig.APIPath = "/apis"    a, err := simple.NewApp(simple.AppConfig{        ManagedKinds: []simple.AppManagedKind{            {                Kind:      v1.MyKindKind(),                Validator: &MyKindValidator{},                Mutator:   &MyKindMutator{},            },        },    })    if err != nil {      return nil, fmt.Errorf("error creating app: %w", err)    }    if err = a.ValidateManifest(cfg.ManifestData); err != nil {        return nil, fmt.Errorf("app manifest validation failed: %w", err)    }    return a, nil}

Note that mutation and validation must also be enabled in the kind's CUE definition (mutation.operations and validation.operations fields) — see the cue-kind-definition skill for details.

Admission Request Fields

Key fields available on app.AdmissionRequest:

FieldTypeDescription
Objectresource.ObjectThe incoming resource (after decoding)
OldObjectresource.ObjectPrevious state (only on UPDATE operations)
Actionresource.AdmissionActionAdmissionActionCreate, AdmissionActionUpdate, AdmissionActionDelete, AdmissionActionConnect
UserInforesource.AdmissionUserInfoThe user making the request
KindstringThe Object kind
GroupstringThe Object API Group
VersionstringThe Object API Version

Validation Patterns

Common patterns to implement:

go
// Immutability checkif req.Action == resource.AdmissionActionUpdate && old.Spec.ImmutableField != obj.Spec.ImmutableField {    return fmt.Errorf("spec.immutableField cannot be changed after creation")}
// Cross-field validationif obj.Spec.StartTime.After(obj.Spec.EndTime) {    return fmt.Errorf("spec.startTime must be before spec.endTime")}
// Referential validation (e.g. check referenced resource exists)if _, err := v.client.Get(ctx, resource.Identifier{Name: obj.Spec.RefName, Namespace: obj.Namespace}); err != nil {    return fmt.Errorf("referenced resource %q not found", obj.Spec.RefName)}

Deployment Difference

ModeAdmission runtime
Standalone operatorApp starts a webhook server; Kubernetes routes admission requests to it
grafana/appsAdmission handlers are auto-registered as a Kubernetes in-process plugin — no separate server required

The handler code itself is identical in both cases.

Resources

Source and attribution

Source:grafana/skillsinskills/grafana-app-sdk/admission-controlat commit1ccacf2

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from grafana/skills

React 19 Plugin Migration

grafana

Guides migration of a Grafana plugin to React 19 compatibility through ordered build, dependency and source-code steps.

Software Development279updated today

Plugin Bundle Size

grafana

Guides optimisation of Grafana app plugin bundle size using React.lazy, Suspense and webpack code splitting.

Software Development279updated today

Grafana Scenes

grafana

Builds Grafana plugin pages with the @grafana/scenes framework, covering scenes, panels, variables and drilldowns.

Software Development279updated today

Check Npm

grafana

Read-only audit of npm, yarn, or pnpm configuration for supply-chain hardening in a JS/TS repository.

Security279updated today

Mimir

grafana

Guides standing up and operating Grafana Mimir for scalable, multi-tenant, long-term Prometheus and OTLP metrics storage.

DevOps & Cloud279updated today

K6 Trend Analysis

grafana

Analyze Grafana Cloud k6 test run trends over time. Detects slow metric drift (e.g., P95 latency creeping up while still passing thresholds), computes headroom to thresholds, flags anomalies, and recommends threshold tightening. Use when the user asks about test performance trends, wants to know if metrics are degrading, asks whether thresholds should be tightened, or wants a health check across recent runs for a specific test. Trigger on phrases like "how is my test trending", "is P95 getting worse", "check for performance regression", "should I tighten thresholds", "are my tests degrading", "show me trends for test X", "analyze my k6 test runs", or "is my test getting slower". Also trigger when a user asks to check all tests in a project -- run this skill once per test and synthesize.

Awaiting classification279updated today