Official agent skill

Admission Control

by grafana in grafana/skills

A skill your agent uses when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Admission Control

skills CLI
$ npx skills add grafana/skills --skill admission-control -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills admission-control --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-app-sdk/admission-control .claude/skills/admission-control && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
admission-control
GitHub stars
282
Token cost
~1.7k tokens
SKILL.md length
348 words
Files
2 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming…

  • The user asks to write a validator
  • SKILL.md covers Getting Stubs, Validator Interface, Mutating Admission (Mutator) and Registering Admission Handlers, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Implement admission control

What it does

Admission Control is an agent skill from grafana/skills, published by the product's own GitHub organization. Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app. Provides guidance on implementing validation and mutation admission handlers for grafana-app-sdk apps.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/admission-patterns.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting, Webhooks and Cloud networking. It works with Grafana and Kubernetes. The licence is Apache-2.0.

When your agent uses it

  • The user asks to write a validator
  • Implement admission control
  • Write a mutating webhook
  • Add a mutation handler

Example prompts

  • “write a validator”
  • “add validation”
  • “implement admission control”
  • “/admission-control”

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are go and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • pkg.go.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Admission Control loads about 1.7k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 348 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 348 words, ~1,716 tokens.

Download SKILL.mdSave it as .claude/skills/admission-control/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
admission-control
description
Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app. Provides guidance on implementing validation and mutation admission handlers for grafana-app-sdk apps.
license
Apache-2.0

Admission Control

Admission control intercepts resource create/update requests before they are persisted. In grafana-app-sdk there are two types:

  • Validation — accept or reject a request; cannot modify the resource
  • Mutation — modify the resource before it is persisted (e.g. set defaults, normalize fields)

The app business logic for admission is identical whether the app runs as a standalone operator or inside grafana/apps. The only difference is the runtime: standalone apps stand up their own webhook server; grafana/apps apps have admission auto-registered as a Kubernetes plugin.

Getting Stubs

For standalone apps, if pkg/app/app.go does not yet exist, a stub App can be generated with:

bash
grafana-app-sdk project component add operator

This creates scaffolded simple.App which admission handlers can be added to for each kind in ManagedKinds.

Validator Interface

go
// Implement this interface for each kind you want to validate
type Validator interface {
    Validate(ctx context.Context, request *app.AdmissionRequest) error
}
  • Return nil to admit the request
  • Return an error to reject it (the error message is returned to the API caller)
  • app.AdmissionRequest provides access to the incoming object and operation type
  • You can use k8s.NewAdmissionError(err error, statusCode int, reason string) (from "github.com/grafana/grafana-app-sdk/k8s") to better control the returned error information
Validator Example
go
type MyKindValidator struct{}

func (v *MyKindValidator) Validate(ctx context.Context, req *app.AdmissionRequest) error {
    obj, ok := req.Object.(*v1.MyKind)
    if !ok {
        return fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)
    }

    // Validate spec fields
    if obj.Spec.Title == "" {
        return fmt.Errorf("spec.title is required")
    }

    if obj.Spec.Count < 0 {
        return fmt.Errorf("spec.count must be non-negative, got %d", obj.Spec.Count)
    }

    // Distinguish create vs update
    if req.Action == resource.AdmissionActionUpdate && req.OldObject != nil {
        old, ok := req.OldObject.(*v1.MyKind)
        if !ok {
            return fmt.Errorf("admission request old object was of invalid type %T (expected *v1.MyKind)", req.OldObject)
        }
        if old.Spec.Title != obj.Spec.Title {
            return fmt.Errorf("spec.title is immutable after creation")
        }
    }

    return nil
}

Mutating Admission (Mutator)

go
// Implement this interface to mutate resources before persistence
type Mutator interface {
    Mutate(ctx context.Context, request *app.AdmissionRequest) (*app.MutatingResponse, error)
}
  • Return a MutatingResponse containing the (optionally modified) object
  • Return an error to reject the request entirely
  • Best practice is to reject requests from validators, not mutators
Mutating Handler Example
go
type MyKindMutator struct{}

func (m *MyKindMutator) Mutate(
    ctx context.Context,
    req *app.AdmissionRequest,
) (*app.MutatingResponse, error) {
    obj, ok := req.Object.(*v1.MyKind)
    if !ok {
        return nil, fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)
    }

    // Set defaults on create
    if req.Action == resource.AdmissionActionCreate {
        if obj.Spec.Description == "" {
            obj.Spec.Description = "No description provided"
        }
    }

    return &app.MutatingResponse{UpdatedObject: obj}, nil
}

Registering Admission Handlers

Register validators and mutators when building the app in pkg/app/app.go:

go
func New(cfg app.Config) (app.App, error) {
    cfg.KubeConfig.APIPath = "/apis"
    a, err := simple.NewApp(simple.AppConfig{
        ManagedKinds: []simple.AppManagedKind{
            {
                Kind:      v1.MyKindKind(),
                Validator: &MyKindValidator{},
                Mutator:   &MyKindMutator{},
            },
        },
    })
    if err != nil {
      return nil, fmt.Errorf("error creating app: %w", err)
    }
    if err = a.ValidateManifest(cfg.ManifestData); err != nil {
        return nil, fmt.Errorf("app manifest validation failed: %w", err)
    }
    return a, nil
}

Note that mutation and validation must also be enabled in the kind's CUE definition (mutation.operations and validation.operations fields) — see the cue-kind-definition skill for details.

Admission Request Fields

Key fields available on app.AdmissionRequest:

FieldTypeDescription
Objectresource.ObjectThe incoming resource (after decoding)
OldObjectresource.ObjectPrevious state (only on UPDATE operations)
Actionresource.AdmissionActionAdmissionActionCreate, AdmissionActionUpdate, AdmissionActionDelete, AdmissionActionConnect
UserInforesource.AdmissionUserInfoThe user making the request
KindstringThe Object kind
GroupstringThe Object API Group
VersionstringThe Object API Version

Validation Patterns

Common patterns to implement:

go
// Immutability check
if req.Action == resource.AdmissionActionUpdate && old.Spec.ImmutableField != obj.Spec.ImmutableField {
    return fmt.Errorf("spec.immutableField cannot be changed after creation")
}

// Cross-field validation
if obj.Spec.StartTime.After(obj.Spec.EndTime) {
    return fmt.Errorf("spec.startTime must be before spec.endTime")
}

// Referential validation (e.g. check referenced resource exists)
if _, err := v.client.Get(ctx, resource.Identifier{Name: obj.Spec.RefName, Namespace: obj.Namespace}); err != nil {
    return fmt.Errorf("referenced resource %q not found", obj.Spec.RefName)
}

Deployment Difference

ModeAdmission runtime
Standalone operatorApp starts a webhook server; Kubernetes routes admission requests to it
grafana/appsAdmission handlers are auto-registered as a Kubernetes in-process plugin — no separate server required

The handler code itself is identical in both cases.

Resources

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/grafana-app-sdk/admission-control of grafana/skills.

  • SKILL.md
  • references/admission-patterns.md

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Admission Control next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Admission Control compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Admission Control this skillgrafana/skills282—~1.7kAutomated safety check: PassApache-2.0
Cloud Infra Supply Chainzhaji2333/CkSKILLS115—~688Automated safety check: WarnMIT
Prometheus GrafanaBagelHole/DevOps-Security-Agent-Skills1.2k—~2.5kAutomated safety check: PassMIT
Grafana Dashboardpando85/kaniop132—~987Automated safety check: PassAGPL-3.0
Qdrant Monitoring Setupqdrant/skills2542 repos~874Automated safety check: PassApache-2.0
Loki Loggingsickn33/agentic-awesome-skills47k1 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    115 GitHub stars~688 tokensUpdated 26 days ago
    DevOps & CloudAuto-check: warnings
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.2k GitHub stars~2.5k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Grafana Dashboard

    pando85/kaniop

    Improve and validate the Kaniop Grafana dashboard against repository metrics and the grigri live cluster.

    132 GitHub stars~987 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Guides Qdrant monitoring setup including Prometheus scraping, health probes, Hybrid Cloud metrics, alerting, and log centralization.

    254 GitHub starsUsed in 2 repos~874 tokens
    DevOps & CloudAuto-check passed
  • Loki Logging

    sickn33/agentic-awesome-skills

    Configure Grafana Loki for log aggregation and analysis. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check passed
  • Prometheus Grafana

    sickn33/agentic-awesome-skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    47k GitHub starsUsed in 1 repo~2.7k tokens
    DevOps & CloudAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    282 GitHub stars~678 tokensUpdated 2 days ago
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    282 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    282 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    282 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    282 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Questions about Admission Control

What does Admission Control do?

A skill your agent uses when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming…. Admission Control is an agent skill from grafana/skills, published by the product's own GitHub organization. Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app.

When should I use Admission Control?

Admission Control fits situations like: the user asks to write a validator; implement admission control; write a mutating webhook; add a mutation handler.

How do I install Admission Control in Claude Code?

Run `npx skills add grafana/skills --skill admission-control -a claude-code`. Or copy the skill folder (skills/grafana-app-sdk/admission-control in grafana/skills) into .claude/skills/admission-control in your project. Claude Code loads it when a task matches its description.

How do I install Admission Control in Codex?

Run `npx skills add grafana/skills --skill admission-control -a codex`. Or copy the skill folder (skills/grafana-app-sdk/admission-control in grafana/skills) into .agents/skills/admission-control in your project. Codex loads it when a task matches its description.

Can I use Admission Control in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill admission-control -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admission-control, .gemini/skills/admission-control, .github/skills/admission-control and .opencode/skills/admission-control in your project.

What does Admission Control need to run?

SKILL.md names no scripts, command-line tools or credentials: Admission Control is instructions for the agent only.

Does Admission Control access the network?

SKILL.md names 2 domains. As links in the text: github.com and pkg.go.dev. This is read from the text; nothing was executed.

Is Admission Control safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Admission Control use?

Admission Control is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Admission Control use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Admission Control?

Skills that share tags, products or a category with Admission Control: Cloud Infra Supply Chain (zhaji2333/CkSKILLS, 115 stars), Prometheus Grafana (BagelHole/DevOps-Security-Agent-Skills, 1.2k stars), Grafana Dashboard (pando85/kaniop, 132 stars) and Qdrant Monitoring Setup (qdrant/skills, 254 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Admission Control?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.