[{"data":1,"prerenderedAt":394},["ShallowReactive",2],{"blog-en-shadow-ai-kubernetes-admission-control-governance":3,"blog-related-en-shadow-ai-kubernetes-admission-control-governance":343,"blog-en-shadow-ai-kubernetes-admission-control-governance-alt":331},{"id":4,"title":5,"author":6,"body":7,"date":325,"description":326,"extension":327,"image":328,"locale":329,"meta":330,"navigation":331,"path":332,"seo":333,"stem":334,"tags":335,"__hash__":342},"blog\u002Fblog\u002Fen\u002Fshadow-ai-kubernetes-admission-control-governance.md","Rogue Deployments Are Wrecking Your Company: The Shadow AI Problem Inside Kubernetes Clusters, and Admission Control as the Fix","Kubo Team",{"type":8,"value":9,"toc":310},"minimark",[10,15,27,30,46,49,53,59,62,70,75,78,82,89,93,96,99,108,112,118,127,140,155,159,168,194,203,206,210,216,225,228,250,261,270,274,277,297],[11,12,14],"h2",{"id":13},"wait-who-deployed-this-ai-tool-shadow-ai-is-no-longer-just-watercooler-talk","\"Wait, Who Deployed This AI Tool?\" — Shadow AI Is No Longer Just Watercooler Talk",[16,17,21],"p",{"className":18,"dir":20},[19],"content-paragraph","ltr",[22,23],"img",{"src":24,"alt":25,"width":26,"height":26},"https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fshadow-ai-kubernetes-admission-control-governance\u002Fsection01.webp","","inherit",[16,28,29],{},"\"We've got AI tools running somewhere in this company that nobody signed off on.\" That sentiment is becoming more common, not less. Shadow AI — employees adopting AI tools without IT's blessing — is no longer a problem confined to a handful of bleeding-edge companies.",[16,31,32,33,40,41,45],{},"According to ",[34,35,39],"a",{"href":36,"rel":37},"https:\u002F\u002Fwww.wiz.io\u002Facademy\u002Fai-security\u002Fshadow-ai",[38],"nofollow","Deloitte's 2026 research",", employee AI usage jumped 50% year-over-year in 2025 alone, yet only one in five organizations has a mature governance model in place. And this isn't limited to unauthorized SaaS apps — the same pattern is spreading directly into engineering teams' hands, inside ",[42,43,44],"strong",{},"Kubernetes clusters themselves",".",[16,47,48],{},"This article reframes shadow AI as more than a SaaS-layer issue. It's a \"rogue deployment\" problem happening in day-to-day Kubernetes operations, and we'll walk through the technical fix: Admission Control.",[11,50,52],{"id":51},"the-rogue-deployments-happening-inside-your-cluster-nobody-knows-whos-running-what","The \"Rogue Deployments\" Happening Inside Your Cluster — Nobody Knows Who's Running What",[16,54,56],{"className":55,"dir":20},[19],[22,57],{"src":58,"alt":25,"width":26,"height":26},"https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fshadow-ai-kubernetes-admission-control-governance\u002Fsection02.webp",[16,60,61],{},"Plenty of alarm bells have already been raised about shadow AI in SaaS. But the exact same pattern is playing out inside Kubernetes clusters.",[16,63,64,65,69],{},"The more enthusiastic a team is about experimenting with generative AI, the more likely its members are to ",[66,67,68],"code",{},"kubectl apply"," inference endpoints, AI agents, and batch jobs on their own judgment. Pods that multiply without an administrator's knowledge create three risks simultaneously.",[71,72,74],"h3",{"id":73},"resource-contention","Resource Contention",[16,76,77],{},"Rogue pods consume GPU and memory, leaving legitimate workloads stuck waiting for scheduling they never expected to need.",[71,79,81],{"id":80},"security-gaps","Security Gaps",[16,83,84,85,88],{},"Pods deployed in a hurry often skip ",[66,86,87],{},"securityContext"," configuration entirely, frequently running in privileged mode or as root.",[71,90,92],{"id":91},"cost-overruns","Cost Overruns",[16,94,95],{},"Workloads that nobody budgeted for quietly inflate the monthly cloud bill.",[16,97,98],{},"You can detect the existence of these rogue workloads by continuously scanning container registries and Kubernetes namespaces for ML frameworks and model artifacts. But there's a wide gap between \"we can detect it\" and \"we've actually prevented it.\"",[16,100,101,102,107],{},"A managed K3s platform like ",[34,103,106],{"href":104,"rel":105},"https:\u002F\u002Fkubo.hexabase.io\u002F",[38],"Kubo"," gives you a dashboard view of overall cluster state, making it easier to spot signs of rogue deployment. But visibility alone can't stop the moment of deployment itself.",[11,109,111],{"id":110},"detection-alone-isnt-enough-stopping-things-at-the-front-door-with-admission-control","Detection Alone Isn't Enough — Stopping Things at the \"Front Door\" with Admission Control",[16,113,115],{"className":114,"dir":20},[19],[22,116],{"src":117,"alt":25,"width":26,"height":26},"https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fshadow-ai-kubernetes-admission-control-governance\u002Fsection03.webp",[16,119,120,121,126],{},"As long as your response to shadow AI workloads relies on detection, you're structurally always playing catch-up. One study comparing detection coverage across methods found manual review caught roughly 40%, a CASB (Cloud Access Security Broker) alone caught about 70%, while a dual-gate approach — reviewing at both build time and runtime — achieved 100% detection (per a paper published in ",[34,122,125],{"href":123,"rel":124},"https:\u002F\u002Faijcst.org\u002Findex.php\u002Faijcst\u002Farticle\u002Fview\u002F216",[38],"AIJCST",").",[16,128,129,130,133,134,139],{},"The Kubernetes mechanism that realizes this \"stop it at the front door\" approach is ",[42,131,132],{},"Admission Control",". According to the ",[34,135,138],{"href":136,"rel":137},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Freference\u002Faccess-authn-authz\u002Fadmission-controllers\u002F",[38],"official Kubernetes documentation",", an Admission Controller is a component that intercepts requests to the API server immediately after authentication and authorization, before the resource is persisted. It only acts on create, update, and delete requests, and processes them in two stages: Mutating (modifying content) and Validating (checking validity).",[16,141,142,147,148,151,152,45],{},[34,143,146],{"href":144,"rel":145},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Freference\u002Faccess-authn-authz\u002Fextensible-admission-controllers\u002F",[38],"Dynamic Admission Control"," goes further, letting you flexibly configure which resources are subject to which webhook via ",[66,149,150],{},"ValidatingWebhookConfiguration"," and ",[66,153,154],{},"MutatingWebhookConfiguration",[71,156,158],{"id":157},"kyverno-and-opa-gatekeeper-the-two-leading-policy-engines","Kyverno and OPA Gatekeeper — The Two Leading Policy Engines",[16,160,161,162,167],{},"The two flagship implementations are ",[34,163,166],{"href":164,"rel":165},"https:\u002F\u002Fkyverno.io\u002Fdocs\u002Fguides\u002Fpod-security\u002F",[38],"Kyverno"," and OPA Gatekeeper.",[16,169,170,171,173,174,179,180,183,184,187,188,193],{},"Kyverno can automatically audit or reject pods that run in privileged mode, use root, omit ",[66,172,87],{},", or mount sensitive host directories — exactly the kind of pod an AI agent, its accompanying MCP server, or a gateway container might try to deploy. In fact, ",[34,175,178],{"href":176,"rel":177},"https:\u002F\u002Fkyverno.io\u002Fpolicies\u002Fpod-security\u002Fbaseline\u002Fdisallow-privileged-containers\u002Fdisallow-privileged-containers\u002F",[38],"Kyverno's policy library"," ships with a \"disallow privileged containers\" policy that outright rejects the creation of any pod with ",[66,181,182],{},"securityContext.privileged"," set to ",[66,185,186],{},"true",". ",[34,189,192],{"href":190,"rel":191},"https:\u002F\u002Fwww.cncf.io\u002Fblog\u002F2026\u002F03\u002F19\u002Fpolicy-as-code-flexible-kubernetes-governance-with-kyverno\u002F",[38],"CNCF's blog"," also highlights Kyverno as a case study in flexibly implementing Kubernetes governance through declarative Policy as Code.",[16,195,196,197,202],{},"OPA Gatekeeper, on the other hand, defines violation logic in Rego or CEL through a resource called ",[34,198,201],{"href":199,"rel":200},"https:\u002F\u002Fopen-policy-agent.github.io\u002Fgatekeeper\u002Fwebsite\u002Fdocs\u002Fconstrainttemplates\u002F",[38],"ConstraintTemplate",", then applies concrete constraints to the cluster as Constraint objects. It has a steeper learning curve than Kyverno's declarative YAML, but its strength is extensibility — the same policy engine can be reused for systems beyond Kubernetes.",[16,204,205],{},"Either approach lets you shift from \"noticing a rogue AI workload after it's deployed\" to \"stopping it before it's deployed.\" That design principle holds just as true on a lightweight Kubernetes distribution like K3s, and adopting Admission Control remains the team's responsibility even on a managed Kubernetes platform.",[11,207,209],{"id":208},"governance-without-visibility-isnt-governance","Governance Without Visibility Isn't Governance",[16,211,213],{"className":212,"dir":20},[19],[22,214],{"src":215,"alt":25,"width":26,"height":26},"https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fshadow-ai-kubernetes-admission-control-governance\u002Fsection04.webp",[16,217,218,219,224],{},"Admission Control is a \"seal the entrance\" measure — it doesn't complete governance on its own. One survey found that 83% of healthcare, 86% of financial services, and 91% of public sector respondents recognize unapproved AI tool usage as a serious business and security risk (per ",[34,220,223],{"href":221,"rel":222},"https:\u002F\u002Fwww.globenewswire.com\u002Fnews-release\u002F2026\u002F07\u002F15\u002F3327806\u002F0\u002Fen\u002FHealthcare-Financial-Services-and-Public-Sector-Industries-Face-Greatest-Risks-in-Shadow-AI-and-Data-Sovereignty-New-Nutanix-Data-Shows.html",[38],"Nutanix's research announcement","). Despite that level of concern, governance still lags because organizations have a mechanism to \"stop\" things but no mechanism to \"see\" them.",[16,226,227],{},"Governance that actually works requires at least three elements.",[229,230,231,238,244],"ul",{},[232,233,234,237],"li",{},[42,235,236],{},"RBAC audits",": Regularly review who can deploy to which namespace",[232,239,240,243],{},[42,241,242],{},"Audit logging",": Make it possible to trace after the fact who deployed what and when",[232,245,246,249],{},[42,247,248],{},"Resource quotas",": Cap CPU\u002Fmemory\u002FGPU per namespace to prevent unbounded growth",[16,251,252,253,256,257,260],{},"Managing these elements separately with disconnected tools just brings you back to the original problem: nobody can see the full picture. This is where a unified view like ",[34,254,106],{"href":104,"rel":255},[38],"'s Captain UI — which visualizes the entire cluster's state on a single screen — delivers real practical value. Running EKS or AKS yourself means building and maintaining separate tools for visibility, auditing, and policy enforcement; ",[34,258,106],{"href":104,"rel":259},[38]," delivers that same operational foundation on top of full K3s-based Kubernetes functionality, starting at roughly $320\u002Fmonth.",[16,262,263,264,269],{},"For organizations running AI workloads, pairing this with an AI agent execution platform like ",[34,265,268],{"href":266,"rel":267},"https:\u002F\u002Fwww.hexabase.com\u002Fproduct\u002Fcaptain-ai\u002F",[38],"Captain.AI"," makes it realistic to manage, end to end, exactly which approved AI agent is running on which cluster and how.",[11,271,273],{"id":272},"summary","Summary",[16,275,276],{},"Shadow AI is usually framed as employees using unapproved SaaS tools, but the same dynamic holds true inside Kubernetes clusters. Since the root cause is a governance failure — not knowing who deployed what, where — the fix needs to happen at the infrastructure level too.",[229,278,279,285,291],{},[232,280,281,284],{},[42,282,283],{},"Front-door defense",": Stop deployments before they happen with Admission Control (Kyverno \u002F OPA Gatekeeper)",[232,286,287,290],{},[42,288,289],{},"Operational defense",": Secure visibility with RBAC, audit logs, and resource quotas",[232,292,293,296],{},[42,294,295],{},"Platform choice",": Pick a managed Kubernetes platform that makes visibility and operations easy",[16,298,299,300,303,304,309],{},"Building your own governance foundation on top of the cost and complexity of EKS\u002FAKS is a heavy lift. ",[34,301,106],{"href":104,"rel":302},[38],", built on K3s, delivers full Kubernetes functionality with visualized governance at dramatically better cost efficiency. If you're not sure what's actually happening inside your cluster right now, ",[34,305,308],{"href":306,"rel":307},"https:\u002F\u002Fwww.hexabase.com\u002Fcontact-us\u002F",[38],"reach out"," and let's talk.",{"title":25,"searchDepth":311,"depth":311,"links":312},2,[313,314,320,323,324],{"id":13,"depth":311,"text":14},{"id":51,"depth":311,"text":52,"children":315},[316,318,319],{"id":73,"depth":317,"text":74},3,{"id":80,"depth":317,"text":81},{"id":91,"depth":317,"text":92},{"id":110,"depth":311,"text":111,"children":321},[322],{"id":157,"depth":317,"text":158},{"id":208,"depth":311,"text":209},{"id":272,"depth":311,"text":273},"2026-07-17","Shadow AI isn't just unauthorized SaaS tools. It's happening inside your Kubernetes clusters too. Here's the risk it creates, and how Admission Control turns detection into real governance.","md","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fshadow-ai-kubernetes-admission-control-governance\u002Feyecatch.webp","en",{},true,"\u002Fblog\u002Fen\u002Fshadow-ai-kubernetes-admission-control-governance",{"title":5,"description":326},"blog\u002Fen\u002Fshadow-ai-kubernetes-admission-control-governance",[336,337,338,339,340,341],"kubernetes","k3s","shadow-ai","admission-control","kyverno","security","7Zdy8VOpob6k6EPnsKrrG8U6neUKlFwLmFPAjGrKN_U",[344,352,360,368,377,386],{"path":345,"title":346,"description":347,"date":348,"tags":349},"\u002Fblog\u002Fen\u002Fkubernetes-certificate-management-cert-manager-process-debt","The Cert Renewal Took One Line of Code and Two Months of Meetings: Why Kubernetes Certificate Management Is a Process Problem, Not a Technical One","Kubernetes certificate management is technically a matter of days. What actually takes time is the organizational process of getting sign-off. Here's how cert-manager automates the technical side, and how to design away the operational debt that remains.","2026-08-09",[337,336,350,351,341],"cert-manager","tls",{"path":353,"title":354,"description":355,"date":356,"tags":357},"\u002Fblog\u002Fen\u002Fai-agent-sandbox-kata-containers-kubernetes","AI Agent Code Isn't a \"Trusted Product\" Anymore. Kubernetes Sandbox Design Has an Answer","Code generated and executed by AI agents can no longer be treated as a trusted, reviewed product. This article explains the limits of container isolation and why Kata Containers' microVM isolation is becoming essential when designing AI agent sandboxes on Kubernetes.","2026-08-08",[337,336,358,359,341],"kata-containers","ai-agent",{"path":361,"title":362,"description":363,"date":364,"tags":365},"\u002Fblog\u002Fen\u002Fkubernetes-image-signing-sigstore-supply-chain","Anyone Can Rewrite an Image Tag. Why Kubernetes Needs Sigstore-Backed Signing to Prove Provenance","Container image signing explained: tags can be overwritten by anyone, and passing CI tests doesn't guarantee the image running in production is the one you built. Learn how Sigstore and Kyverno work together to reject unsigned images on Kubernetes\u002FK3s, integrated into a GitOps workflow.","2026-08-06",[337,336,366,367,341],"ci-cd","gitops",{"path":369,"title":370,"description":371,"date":372,"tags":373},"\u002Fblog\u002Fen\u002Fkubernetes-secrets-rbac-etcd-encryption","Base64 Isn't Encryption: Why Kubernetes Secrets Pass Right Through, and the RBAC Design Traps That Make It Worse","Kubernetes Secrets are only Base64-encoded, not encrypted. Learn how plaintext-equivalent storage in etcd and over-permissioned RBAC lead to real incidents, plus the concrete Secrets management practices you need for production K3s.","2026-07-29",[336,337,374,375,341,376],"secrets-management","rbac","etcd-encryption",{"path":378,"title":379,"description":380,"date":381,"tags":382},"\u002Fblog\u002Fen\u002Fkubernetes-v136-k3s-managed-cost-reduction","Managed Kubernetes is Too Expensive. The Reality of 'Full K8s Operations Under $400\u002FMonth' with K3s Lightweight and v1.36 Security Enhancements","Explore how to leverage Kubernetes v1.36 'Haru' enhanced User Namespaces and security features in K3s lightweight environments. Discover managed K3s operational strategies and 2026 infrastructure selection guidelines that achieve 60% cost reduction compared to EKS.","2026-05-28",[337,336,383,384,385,341],"kubernetes-v136","managed-kubernetes","cost-optimization",{"path":387,"title":388,"description":389,"date":390,"tags":391},"\u002Fblog\u002Fen\u002Fkubevirt-calico-live-migration-networking","Moving a VM Doesn't Have to Break the Connection: Inside KubeVirt and Calico's Live Migration Magic","Why doesn't live migrating a VM (KubeVirt) between Kubernetes nodes break the connection? We break down Calico's IP persistence and BGP route convergence, and what it means for teams moving off VMware.","2026-08-07",[337,336,392,393,384],"kubevirt","networking",1786354657695]