Create a ValidatingWebhookConfiguration whose rules match the kinds you want to read, or patch an existing one to point at your endpoint and inherit its rules and CA trust.
Validating webhooks receive the full object, so Secret and ConfigMap contents leave the cluster on every admission.
The configuration write and each triggering request are both recorded in the audit log.
What no Kubernetes log holds is the payload sent outbound, so the copy itself leaves no cluster-side record.
failurePolicy Ignore keeps admission working when the endpoint is unreachable, which is what makes it quiet.
Rights needed, any one set:
· any one; a new configuration whose rules you choose
· scoped to redirecting clientConfig on a configuration that already matches the kinds you want
· any one; inherits the existing rules and CA trust rather than declaring new ones

