OPA Gatekeeper requires learning Rego. Kyverno writes policies in YAML ā the same language you already use for Kubernetes resources. Lower barrier, same enforcement power.
Installation
helm install kyverno kyverno/kyverno \
--namespace kyverno --create-namespaceValidation: Block Bad Resources
Require Labels
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-labels
spec:
validationFailureAction: Enforce
rules:
- name: require-team-label
match:
any:
- resources:
kinds: ["Deployment", "StatefulSet"]
validate:
message: "Label 'team' is required"
pattern:
metadata:
labels:
team: "?*"Deploy without a team label ā rejected.
Block Latest Tag
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: disallow-latest-tag
spec:
validationFailureAction: Enforce
rules:
- name: validate-image-tag
match:
any:
- resources:
kinds: ["Pod"]
validate:
message: "Images must use a specific tag, not ':latest'"
pattern:
spec:
containers:
- image: "!*:latest"Restrict Registries
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: allowed-registries
spec:
validationFailureAction: Enforce
rules:
- name: validate-registry
match:
any:
- resources:
kinds: ["Pod"]
validate:
message: "Images must come from approved registries"
pattern:
spec:
containers:
- image: "registry.myorg.com/* | ghcr.io/myorg/*"Master this topic with hands-on labs
Go beyond reading ā build real projects in sandboxed environments with expert video guidance.
Browse Courses āMutation: Set Defaults
Add Default Resource Limits
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: add-default-limits
spec:
rules:
- name: set-memory-limit
match:
any:
- resources:
kinds: ["Pod"]
mutate:
patchStrategicMerge:
spec:
containers:
- (name): "*"
resources:
limits:
memory: "512Mi"
requests:
memory: "256Mi"Pods without resource limits automatically get defaults. Developers do not need to remember ā the policy handles it.
Inject Sidecar
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: inject-logging-sidecar
spec:
rules:
- name: inject-fluentbit
match:
any:
- resources:
kinds: ["Deployment"]
selector:
matchLabels:
logging: enabled
mutate:
patchStrategicMerge:
spec:
template:
spec:
containers:
- name: fluentbit
image: fluent/fluent-bit:latest
volumeMounts:
- name: logs
mountPath: /var/log/appGeneration: Create Resources Automatically
Auto-Create NetworkPolicy
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: generate-networkpolicy
spec:
rules:
- name: default-deny
match:
any:
- resources:
kinds: ["Namespace"]
generate:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
name: default-deny
namespace: "{{request.object.metadata.name}}"
data:
spec:
podSelector: {}
policyTypes:
- Ingress
- EgressEvery new namespace automatically gets a default-deny NetworkPolicy.
Auto-Create ResourceQuota
- name: generate-quota
match:
any:
- resources:
kinds: ["Namespace"]
generate:
apiVersion: v1
kind: ResourceQuota
name: default-quota
namespace: "{{request.object.metadata.name}}"
data:
spec:
hard:
requests.cpu: "4"
requests.memory: "8Gi"
limits.cpu: "8"
limits.memory: "16Gi"Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps ā curated insights delivered to your inbox. No spam.
Subscribe Free āAudit Mode
Test policies without blocking:
spec:
validationFailureAction: Audit # Log violations, don't block# View policy violations
kubectl get policyreport -ASwitch to Enforce once violations are resolved.
Kyverno vs OPA Gatekeeper
| Feature | Kyverno | OPA Gatekeeper |
|---|---|---|
| Policy language | YAML | Rego |
| Learning curve | Low | High |
| Validation | ā | ā |
| Mutation | ā | Limited |
| Generation | ā | ā |
| Image verification | ā | ā |
| Audit reports | PolicyReport CRD | Constraint status |
Kyverno is easier to adopt and covers more use cases (mutation + generation). Gatekeeper's Rego is more powerful for complex logic.
---
Ready to go deeper? Master Kubernetes security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials ā start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
OPA Gatekeeper Kubernetes Policies
OPA Gatekeeper enforces custom policies in Kubernetes at admission time. Learn how to write ConstraintTemplates, enforce security standards, and prevent.
Talos Linux for Kubernetes
Talos Linux is a minimal, immutable OS designed exclusively for running Kubernetes. Learn why it exists, how it works, and when to use it instead of Ubuntu.
Falco Runtime Security Kubernetes
Falco detects runtime threats in Kubernetes using eBPF. Learn how to set up Falco for container security monitoring, write custom rules, and integrate.
Learn Ansible Free: Beginner Guide
Start learning Ansible for free with hands-on examples. Master playbooks, inventory, modules, and roles to automate infrastructure.
Linkerd Lightweight Service Mesh
Linkerd is the lightest Kubernetes service mesh with automatic mTLS, golden metrics, and zero-config retries. Learn how Linkerd compares to Istio and when its.
Linux Cron Jobs Complete Guide
Master Linux cron jobs for scheduling. Crontab syntax, common patterns, error handling, output logging, and systemd timer alternatives.
Explore topics
Browse more articles on the topics covered here.