Skip to main content
← All posts·
Platform Engineering

OPA Gatekeeper for Kubernetes Compliance: Policy Enforcement Guide [2026]

How to use OPA Gatekeeper for Kubernetes policy enforcement in regulated enterprises. Covers admission control policies, compliance-as-code for DORA/NIS2, pod security enforcement, image allowlisting, and integration with CI/CD pipelines.

Luca Berton11 min read

Policy Enforcement: Where Compliance Meets Kubernetes

In regulated enterprises, it's not enough to document security policies — you need to enforce them automatically. OPA Gatekeeper is a Kubernetes admission controller that rejects non-compliant resources before they're created. If a developer tries to deploy a container running as root, without resource limits, or from an untrusted registry — Gatekeeper blocks it.

How Gatekeeper Works

Gatekeeper intercepts Kubernetes API requests as a validating admission webhook:

  1. Developer creates a Pod/Deployment (kubectl apply or GitOps)
  2. Kubernetes API server sends the request to Gatekeeper before storing it
  3. Gatekeeper evaluates the request against defined policies (ConstraintTemplates)
  4. If the request violates a policy → rejected with a clear error message
  5. If the request passes all policies → allowed to proceed

Key distinction: Gatekeeper is preventive, not detective. It stops non-compliant resources from being created rather than finding them after the fact.

Essential Policies for Regulated Environments

Security Policies

  • No privileged containers — Block containers running with privileged: true
  • No root users — Require runAsNonRoot: true on all containers
  • Read-only root filesystem — Enforce readOnlyRootFilesystem: true where possible
  • No host networking/PID/IPC — Block pods that share host namespaces
  • Drop all capabilities — Require explicit capability additions, deny ALL by default
  • Image allowlisting — Only allow images from approved registries (e.g., your private ECR/ACR/GCR)
  • No latest tag — Require specific image tags or digests for reproducibility

Resource Management Policies

  • Required resource requests/limits — Every container must specify CPU and memory requests and limits
  • Maximum resource limits — Prevent any single pod from consuming excessive cluster resources
  • Required labels — Enforce team, project, and cost-centre labels for cost allocation and audit
  • Required probes — Mandate liveness and readiness probes on all production workloads

Compliance-Specific Policies

  • DORA — Audit logging: Require sidecar or annotation for audit log collection on critical workloads
  • NIS2 — Encryption: Block services without TLS termination (Istio mTLS or Ingress TLS required)
  • GDPR — Data residency: Restrict nodeSelector/affinity to approved regions for workloads processing personal data
  • CRA — SBOM: Require image annotations containing SBOM references
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

Gatekeeper vs Kyverno

AspectGatekeeper (OPA)Kyverno
Policy languageRego (OPA's policy language)YAML (Kubernetes-native)
Learning curveSteeper (Rego is a new language)Lower (YAML-based policies)
MutationSupported (mutation webhooks)First-class (mutate + validate)
GenerationLimitedCan generate resources (NetworkPolicies, etc.)
EcosystemOPA is used beyond K8s (API gateways, CI/CD)Kubernetes-only

Choose Gatekeeper if: You want OPA's broader ecosystem (use same policies in CI/CD, API gateways, Terraform). Choose Kyverno if: You want simpler YAML-based policies and resource generation capabilities.

Implementation Roadmap

  1. Week 1: Install Gatekeeper in audit mode (dryrun) — policies log violations but don't block
  2. Week 2: Deploy the Gatekeeper library's standard policies (no privileged, no root, resource limits)
  3. Week 3: Review violations, work with teams to remediate existing non-compliant resources
  4. Week 4: Switch critical policies to enforcement mode (deny). Keep less critical policies in audit.
  5. Ongoing: Add custom policies for your regulatory requirements, integrate with CI/CD for shift-left validation.
🎓 Course

Evaluating RAG Solutions

Choose the right RAG model, configure, test, and optimise.

Start on Pluralsight →
OPA
Gatekeeper
Kubernetes
policy enforcement
compliance
admission control
regulated enterprises

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →