Kubernetes Policy Without Learning a New Language
OPA Gatekeeper requires learning Rego — a purpose-built policy language. For many platform teams, this is a barrier to adoption. Kyverno takes a different approach: policies are written in YAML, the same language Kubernetes administrators already use every day. For regulated enterprises that need rapid policy adoption without specialised Rego expertise, Kyverno is compelling.
Kyverno's Three Policy Types
1. Validate — Block Non-Compliant Resources
Validation policies reject resources that don't meet your requirements:
- Pod security: Block privileged containers, require non-root users, enforce read-only root filesystems
- Image policies: Restrict to approved registries, block latest tag, require image digests
- Resource management: Require CPU/memory limits, enforce resource quotas, mandate labels
- Network policies: Require NetworkPolicy objects in every namespace
- Compliance-specific: Enforce data residency labels, require audit logging annotations, mandate TLS
2. Mutate — Fix Resources Automatically
Mutation policies automatically modify resources to comply:
- Add security context: Automatically add runAsNonRoot, drop capabilities, readOnlyRootFilesystem
- Inject labels: Add cost-centre, team, compliance-tier labels automatically
- Add tolerations/affinity: Route workloads to compliant node pools based on data classification
- Set resource defaults: Add default CPU/memory requests if not specified
- Inject sidecars: Automatically add logging or security sidecars to pods
Why this matters: Instead of rejecting and frustrating developers, mutation makes compliance the default. The developer's YAML goes in non-compliant, comes out compliant, without them needing to know the details.
3. Generate — Create Supporting Resources
Generation policies automatically create resources when triggers occur:
- NetworkPolicy: Auto-create default deny NetworkPolicy when a new namespace is created
- ResourceQuota: Auto-create resource quotas for new namespaces
- LimitRange: Auto-create default resource limits for new namespaces
- ConfigMaps/Secrets: Sync configuration across namespaces (e.g., CA certificates, shared config)
- RoleBindings: Auto-bind teams to their namespaces based on labels
Compliance value: Ensures every namespace starts with security baselines — no "forgotten" namespaces without network policies.
Image Verification (Supply Chain Security)
Kyverno can verify container image signatures and attestations:
- Cosign verification: Only allow images signed with your organisation's signing key
- SBOM attestation: Require images to have SBOM attestations (CRA compliance)
- Vulnerability attestation: Block images that haven't passed vulnerability scanning
- Notary/notation: Support for Notary v2 image verification
CRA compliance: The Cyber Resilience Act requires software composition transparency. Kyverno can enforce that every deployed image has a verified SBOM attestation.
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Kyverno vs OPA Gatekeeper
| Feature | Kyverno | OPA Gatekeeper |
|---|---|---|
| Policy language | YAML (Kubernetes-native) | Rego |
| Mutation | First-class, powerful | Supported (newer) |
| Generation | Yes (unique to Kyverno) | No |
| Image verification | Built-in (cosign, notary) | Via external data |
| Adoption barrier | Low (YAML) | Higher (learn Rego) |
| Beyond K8s | Kubernetes only | OPA used in API gateways, CI/CD, Terraform |
See our detailed comparison: OPA Gatekeeper for Kubernetes Compliance.
Getting Started
- Install Kyverno via Helm in audit mode (policies report but don't block)
- Deploy Pod Security Standard policies — Kyverno provides ready-made policies matching K8s Pod Security Standards
- Add generation policies — Default deny NetworkPolicy + ResourceQuota for every new namespace
- Review policy reports — Identify existing non-compliant resources and remediate
- Switch to enforce mode — Once teams have remediated, enable blocking for critical policies
IT Automation with Ansible Quickstart
Automate IT tasks, deploy apps, and streamline workflows in 40 minutes.
Start on Skillshare →
Luca Berton
