one gem from #kubecon2023 is the talk on #kubernetes declarative validation and admission; https://www.youtube.com/watch?v=rFaWmd7Y7i0
2. you can use CEL validation in a stand-alone ValidatingAdmissionPolicy. this allows opt-in validation on native/custom types (so you can e.g. create company wide-policies) - https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/ (beta in 1.28)