5.3. Bypassing admission controller enforcement
To configure a deployment to bypass the admission controller, you must set the admission.stackrox.io/break-glass annotation on the deployment. Bypassing the admission controller triggers a violation of the "StackRox Emergency Deployment Annotation" policy, which includes deployment details.
To help others understand why you bypassed the admission controller, use an issue-tracker link or some other reference as the value of this annotation.
Prerequisites
You have enabled the ability to bypass the admission controller on the secured cluster by using one of the following options:
-
Operator: You set the
admissionControl.bypassparameter toBreakGlassAnnotation. -
Helm: You set the
admissionControl.dynamic.disableBypassparameter tofalse. -
RHACS portal: You set the option in Platform Configuration
Clusters Admission controller bypass annotation to Enabled.
-
Operator: You set the
Procedure
Create a deployment YAML that includes the
admission.stackrox.io/break-glassannotation, as shown in the following example:apiVersion: apps/v1 kind: Deployment metadata: annotations: "admission.stackrox.io/break-glass": "jira-3423" creationTimestamp: "2025-03-07T03:18:21Z" generation: 1 labels: app: hello-node name: hello-node namespace: test-bypass-adm ...where:
metadata.annotations.admission.stackrox.io/break-glass- Specifies a change control reference or relevant explanation for why the admission controller was bypassed.