Delete the ValidatingWebhookConfiguration or MutatingWebhookConfiguration objects that back a policy engine, or patch one to widen failurePolicy or narrow its rules.
Third-party enforcement such as Gatekeeper, Kyverno, or image signature verification stops rejecting anything.
Pod Security Admission is unaffected.
It is a built-in API server controller rather than a webhook, so namespace enforce labels still apply.
On its own this only removes a guard.
It becomes privilege only alongside a verb that creates the workload the webhook was rejecting.
Rights needed, any one set:
· any one; whichever kind backs the policy engine
· any one; whichever kind backs the policy engine
· scoped to widening failurePolicy to Ignore, or narrowing rules so the workload no longer matches
· any one; neutering leaves the object in place, so nothing looks deleted

