Admission controller was restarting every ~5min due to API server timeouts causing leader election loss. failurePolicy:Fail meant the webhook blocked all pod creation cluster-wide when Kyverno was unavailable. |
||
|---|---|---|
| .. | ||
| main.tf | ||
| resource-governance.tf | ||
| security-policies.tf | ||