Threat model
Assets, trust boundaries, and a threat-by-threat table with the control and the residual limitation stated side by side — replayed ALLOW grants, actor and digest substitution, TOCTOU between policy and commit, webhook outage, recovery deadlock, sensitive-manifest disclosure. It says plainly what the webhook cannot do: a hostile cluster-admin can remove the admission configuration, and the default rules deliberately do not intercept admissionregistration resources, so an unavailable webhook can never block its own removal.
