Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • All guides
      • Overview
      • Activating the module KSPM
      • Working with a dashboard
      • Viewing control rules
      • Performing security compliance checks
      • Managing exceptions to control rules
      • Managing rule modes
  • Pricing policy
  • Audit Trails events
  • Release notes

In this article:

  • Enabling Blocking mode
  • Enabling Audit mode
  • Managing lock mode with the help of exceptions
  1. Step-by-step guides
  2. Kubernetes® Security Posture Management (KSPM)
  3. Managing rule modes

Managing the operating modes of security control rules of KSPM

Written by
Yandex Cloud
Updated at July 29, 2026
View in Markdown
  • Enabling Blocking mode
  • Enabling Audit mode
  • Managing lock mode with the help of exceptions

The Admission type security control rules of the KSPM module have two operating modes:

  • Audit: Mode in which a rule violation does not block the deployment of workloads in Kubernetes clusters. Default mode.
  • Blocking: Mode in which a rule violation leads to blocking the deployment of workloads in Kubernetes clusters.

Enabling Blocking modeEnabling Blocking mode

To enable Blocking mode for a rule:

Security Deck UI
  1. Go to Yandex Security Deck.
  2. In the left-hand panel, select  Rules and exceptions.
  3. At the top of the window, select the workspace you want to change the rule mode in.
  4. On the Security control rules page that opens, go to the Kubernetes® tab. In the list that appears, find the Admission type rule whose mode you want to change. Optionally, use the filter at the top of the list.
  5. Click Mode: Audit next to the rule and select Enable block mode.
  6. In the window that opens, confirm enabling lock mode.

You can also change the rule's operating mode in the **Rule type
** field on the rule's detailed info page.

Enabling Audit modeEnabling Audit mode

To enable Audit mode for a rule (if Blocking mode was previously enabled for this rule):

Security Deck UI
  1. Go to Yandex Security Deck.
  2. In the left-hand panel, select  Rules and exceptions.
  3. At the top of the window, select the workspace you want to change the rule mode in.
  4. On the Security control rules page that opens, go to the Kubernetes® tab. In the list that appears, find the Admission type rule whose mode you want to change. Optionally, use the filter at the top of the list.
  5. Click Mode: Blocking next to the rule and select Disable block mode.
  6. In the window that opens, confirm disabling lock mode.

You can also change the rule's operating mode in the **Rule type
** field on the rule's detailed info page.

Managing lock mode with the help of exceptionsManaging lock mode with the help of exceptions

When you activate Blocking mode for a rule, by default it applies to all Kubernetes® clusters in the workspace.

To change this logic and explicitly specify which Kubernetes® resources in the workspace will not be subject to Blocking mode, create an exception to the rule:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select  Rules and exceptions.

  3. At the top of the window, select the workspace in which you want to set up an exception for the security control rule.

  4. On the Security control rules page that opens, navigate to the Kubernetes® tab and select from the list the Admission type rule you want to create an exception for. Optionally, use the filter at the top of the list.

  5. In the rule info window that opens, go to the Exceptions tab and click Create exception.

  6. Under Effect, select the correct lock mode:

    • Ignore rule: Checks for compliance with the rule for the resources named in the exception are off completely; no violations are logged.
    • Disable lock mode for rule: Violations of the rule for the resources named in the exception will be logged, but deployment of workloads in Kubernetes® clusters will not be blocked.
  7. Under Scope, specify the clusters for which to cancel the lock, configure other settings, and complete the exception setup.

    Tip

    If necessary, look up Managing exceptions from KSPM security control rules.

Security Deck workspaces allow you to manage Yandex Cloud infrastructure security in a more granular way. They are containers for settings and resources of Security Deck modules, lists of controlled resources, control parameters, etc. For more information, see Security Deck workspaces.

You can use KSPM exceptions to specify objects you want excluded from the control rules in place. For more information on exceptions, see Managing exceptions from KSPM security control rules.

Was the article helpful?

Previous
Managing exceptions to control rules
Next
Overview
© 2026 Direct Cursus Technology L.L.C.