Kubernetes lets you deploy anything. OPA Gatekeeper lets you define what "anything" should not include — no privileged containers, no latest tags, no missing resource limits, no public load balancers in production.
How Gatekeeper Works
Gatekeeper is a Kubernetes admission controller. Every resource creation or update passes through it before reaching etcd:
kubectl apply → API Server → Gatekeeper (allow/deny) → etcdIf a resource violates a policy, the request is rejected with a clear error message. The resource never exists in the cluster.
Installation
helm install gatekeeper gatekeeper/gatekeeper \
--namespace gatekeeper-system --create-namespaceMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →ConstraintTemplates and Constraints
Gatekeeper uses two objects:
- ConstraintTemplate — defines the policy logic (written in Rego)
- Constraint — applies the template with specific parameters
Example: Block Privileged Containers
apiVersion: templates.gatekeeper.sh/v1
kind: ConstraintTemplate
metadata:
name: k8sblockprivileged
spec:
crd:
spec:
names:
kind: K8sBlockPrivileged
targets:
- target: admission.k8s.gatekeeper.sh
rego: |
package k8sblockprivileged
violation[{"msg": msg}] {
container := input.review.object.spec.containers[_]
container.securityContext.privileged == true
msg := sprintf("Privileged container not allowed: %v", [container.name])
}
violation[{"msg": msg}] {
container := input.review.object.spec.initContainers[_]
container.securityContext.privileged == true
msg := sprintf("Privileged init container not allowed: %v", [container.name])
}apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sBlockPrivileged
metadata:
name: block-privileged-containers
spec:
match:
kinds:
- apiGroups: [""]
kinds: ["Pod"]
namespaces: ["production", "staging"]Now try deploying a privileged container:
$ kubectl apply -f privileged-pod.yaml
Error: admission webhook denied the request:
Privileged container not allowed: my-containerExample: Require Resource Limits
apiVersion: templates.gatekeeper.sh/v1
kind: ConstraintTemplate
metadata:
name: k8srequirelimits
spec:
crd:
spec:
names:
kind: K8sRequireLimits
targets:
- target: admission.k8s.gatekeeper.sh
rego: |
package k8srequirelimits
violation[{"msg": msg}] {
container := input.review.object.spec.containers[_]
not container.resources.limits.cpu
msg := sprintf("Container %v must set CPU limits", [container.name])
}
violation[{"msg": msg}] {
container := input.review.object.spec.containers[_]
not container.resources.limits.memory
msg := sprintf("Container %v must set memory limits", [container.name])
}Example: Block Latest Tag
apiVersion: templates.gatekeeper.sh/v1
kind: ConstraintTemplate
metadata:
name: k8sblocklatesttag
spec:
crd:
spec:
names:
kind: K8sBlockLatestTag
targets:
- target: admission.k8s.gatekeeper.sh
rego: |
package k8sblocklatesttag
violation[{"msg": msg}] {
container := input.review.object.spec.containers[_]
endswith(container.image, ":latest")
msg := sprintf("Image %v uses :latest tag", [container.image])
}
violation[{"msg": msg}] {
container := input.review.object.spec.containers[_]
not contains(container.image, ":")
msg := sprintf("Image %v has no tag (defaults to :latest)", [container.image])
}Audit Mode
Test policies without blocking deployments:
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sBlockLatestTag
metadata:
name: block-latest-tag
spec:
enforcementAction: dryrun # Log violations, don't block
match:
kinds:
- apiGroups: [""]
kinds: ["Pod"]Check violations:
kubectl get k8sblocklatesttag block-latest-tag -o yaml
# status.violations shows all current violationsSwitch to deny once you have fixed existing violations.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Gatekeeper Library
The Gatekeeper community maintains a library of pre-built templates:
# Clone the library
git clone https://github.com/open-policy-agent/gatekeeper-library
# Apply common templates
kubectl apply -f gatekeeper-library/library/Pre-built policies for: container limits, image registries, host networking, privilege escalation, read-only root filesystem, and more.
Gatekeeper vs Kyverno
| Feature | Gatekeeper | Kyverno |
|---|---|---|
| Policy language | Rego | YAML (native K8s) |
| Learning curve | Steep (Rego) | Low (YAML) |
| Mutation | Limited | Full support |
| Generation | No | Yes (create resources) |
| Community | Large (OPA ecosystem) | Growing fast |
Choose Gatekeeper if your team already uses OPA or needs complex policy logic. Choose Kyverno if you want YAML-native policies that are easier to write and maintain.
---
Ready to go deeper? Master Kubernetes security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Kyverno Kubernetes Policy Engine
Kyverno validates, mutates, and generates Kubernetes resources using YAML policies instead of Rego. Learn how to enforce security standards, set defaults.
Talos Linux for Kubernetes
Talos Linux is a minimal, immutable OS designed exclusively for running Kubernetes. Learn why it exists, how it works, and when to use it instead of Ubuntu.
Falco Runtime Security Kubernetes
Falco detects runtime threats in Kubernetes using eBPF. Learn how to set up Falco for container security monitoring, write custom rules, and integrate.
OpenClaw + Ansible Automation
Combine OpenClaw's AI agent with Ansible for intelligent infrastructure automation — writing playbooks, debugging tasks, and orchestrating deployments.
OpenClaw Architecture Deep Dive
Deep dive into OpenClaw's architecture — the gateway, sessions, tool system, memory layer, and channel providers that make it tick.
OpenClaw Browser Automation
Use OpenClaw's browser tool for web automation — scraping, testing, form filling, and monitoring. No Selenium or Puppeteer setup needed.
Explore topics
Browse more articles on the topics covered here.