Admission Control
Admission control intercepts resource create/update requests before they are persisted. In grafana-app-sdk there are two types:
- Validation — accept or reject a request; cannot modify the resource
- Mutation — modify the resource before it is persisted (e.g. set defaults, normalize fields)
The app business logic for admission is identical whether the app runs as a standalone operator or inside grafana/apps. The only difference is the runtime: standalone apps stand up their own webhook server; grafana/apps apps have admission auto-registered as a Kubernetes plugin.
Getting Stubs
For standalone apps, if pkg/app/app.go does not yet exist, a stub App can be generated with:
This creates scaffolded simple.App which admission handlers can be added to for each kind in ManagedKinds.
Validator Interface
- Return
nilto admit the request - Return an error to reject it (the error message is returned to the API caller)
app.AdmissionRequestprovides access to the incoming object and operation type- You can use
k8s.NewAdmissionError(err error, statusCode int, reason string)(from"github.com/grafana/grafana-app-sdk/k8s") to better control the returned error information
Validator Example
Mutating Admission (Mutator)
- Return a
MutatingResponsecontaining the (optionally modified) object - Return an error to reject the request entirely
- Best practice is to reject requests from validators, not mutators
Mutating Handler Example
Registering Admission Handlers
Register validators and mutators when building the app in pkg/app/app.go:
Note that mutation and validation must also be enabled in the kind's CUE definition (mutation.operations and validation.operations fields) — see the cue-kind-definition skill for details.
Admission Request Fields
Key fields available on app.AdmissionRequest:
Validation Patterns
Common patterns to implement:
Deployment Difference
The handler code itself is identical in both cases.


