Most of these tools fail because you edited the wrong file, or the right file on the wrong node. This is the map I keep next to the cluster.
The centre of gravity is /etc/kubernetes/, especially manifests/kube-apiserver.yaml. Almost every admission plugin, audit log, and webhook client starts there.
kubectl get constrainttemplateskubectl get constraintskubectl get validatingadmissionwebhookskubectl get mutatingadmissionwebhookskubectl get namespace --show-labels
If you cannot remember a path, find /etc/kubernetes /etc/falco /etc/apparmor.d -type f on the node is faster than guessing. Confirm the file exists on the node that actually runs the process — API server configs on the control plane, AppArmor and seccomp on the worker that will host the pod.