admission webhook denied the request ☸️ Kubernetes

Error from server: admission webhook "validate.nginx.ingress.kubernetes.io" denied the request

A validating admission webhook (ingress-nginx, Gatekeeper/OPA, Kyverno) inspected your object and rejected it; the reason follows in the message.

Seen on: Kubernetes

Meaning

Admission webhooks enforce rules beyond the API schema: duplicate Ingress host/path, disallowed images, missing labels or resource limits, forbidden annotations (ingress-nginx blocks risky snippet annotations by default).

Common causes

  • Policy violation (Kyverno/Gatekeeper rule)
  • ingress-nginx: host/path already defined in another Ingress, or snippet annotations disabled
  • Invalid nginx configuration generated by annotations

⚡ Quick fix

  1. Read the reason after “denied the request:”
  2. Fix the object to satisfy the policy
  3. Ask the platform team for an exception if needed

Detailed fix by platform

Kubernetes

  1. bash
    kubectl apply --dry-run=server -f ingress.yaml
    kubectl get validatingwebhookconfigurations

How to diagnose

  1. Webhook — Which one denied?
  2. Reason — Rule or nginx config error text

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.