Tool Open source
Kyverno is a Kubernetes-native policy engine for platform engineering teams that manages security, compliance, automation, and governance through policy as code. It uses Kubernetes admission controls and background scans to validate, mutate, generate, and clean up resources, and can verify container image signatures for supply-chain security. Kyverno works with tools including kubectl, Kustomize, and Git; its policies can enforce standards such as Pod Security Standards, security contexts, naming conventions, resource limits, image sources and signatures, and required workload probes. It complements Kubernetes RBAC and native ValidatingAdmissionPolicies and MutatingAdmissionPolicies rather than replacing them, and only enforces requirements explicitly defined in maintained policies.
2 uses taken from transcripts — each links to the moment in the video.
Automatically enforces hard policies before every infrastructure change, blocking prohibited configurations regardless of who or what submitted them.
A Kubernetes policy engine used for validating admission policies and, through its CLI, checking configurations before they are applied to a cluster.
2 in the library.