kyverno

kyverno

Kubernetes-native policy management

Policies are managed as Kubernetes resources


Policies

Kyverno manages community policies

These policies are searchable

Examples

Check for deprecated APIs

Require specific labels on resources

Allowlist for image registries

Require attestations of security scans


Demo

kyverno for the Pod Security Standards

Keyless image signatures using sigstore