kyverno

module
v1.18.3-0...-8363104 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 28, 2026 License: Apache-2.0

README ΒΆ

Kyverno Tweet

Cloud Native Policy Management πŸŽ‰

Build Status Go Report Card GitHub Repo stars CII Best Practices OpenSSF Scorecard SLSA 3 Artifact HUB codecov FOSSA Status

Kyverno Logo

πŸ“‘ Table of Contents

About Kyverno

Kyverno is a Kubernetes-native policy engine designed for platform engineering teams. It enables security, compliance, automation, and governance through policy-as-code. Kyverno can:

  • Validate, mutate, generate, and clean up resources using Kubernetes admission controls and background scans.
  • Verify container image signatures for supply chain security.
  • Operate with tools you already use β€” like kubectl, kustomize, and Git.
Open Source Security Index badge

πŸ“™ Documentation

Kyverno installation and reference documentation is available at kyverno.io.

πŸŽ₯ Demos & Tutorials

Kyverno helps platform teams enforce best practices and security standards. Some common use cases include:

1. Security & Compliance
  • Enforce Pod Security Standards (PSS)
  • Require specific security contexts
  • Validate container image sources and signatures
  • Enforce CIS Benchmark policies
2. Operational Excellence
  • Auto-label workloads
  • Enforce naming conventions
  • Generate default configurations (e.g., NetworkPolicies)
  • Validate YAML and Helm manifests
3. Cost Optimization
  • Enforce resource quotas and limits
  • Require cost allocation labels
  • Validate instance types
  • Clean up unused resources
4. Developer Guardrails
  • Require readiness/liveness probes
  • Enforce ingress/egress policies
  • Validate container image versions
  • Auto-inject config maps or secrets

πŸ“š Explore the Policy Library

Discover hundreds of production-ready Kyverno policies for security, operations, cost control, and developer enablement.

πŸ‘‰ Browse the Policy Library

πŸ™‹ Getting Help

We’re here to help:

βž• Contributing

Thank you for your interest in contributing to Kyverno!

🧾 Software Bill of Materials

All Kyverno images include a Software Bill of Materials (SBOM) in CycloneDX format. SBOMs are available at:

πŸ‘₯ Contributors

Kyverno is built and maintained by our growing community of contributors!

Contributors image

Made with contributors-img

πŸ“„ License

Copyright 2026, the Kyverno project. All rights reserved.
Kyverno is licensed under the Apache License 2.0.

Kyverno is a Cloud Native Computing Foundation (CNCF) Incubating project and was contributed by Nirmata.

Directories ΒΆ

Path Synopsis
api
kyverno/v1beta1
Package v1beta1 contains API Schema definitions for the policy v1beta1 API group +k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=kyverno.io
Package v1beta1 contains API Schema definitions for the policy v1beta1 API group +k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=kyverno.io
kyverno/v2
+k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=kyverno.io
+k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=kyverno.io
kyverno/v2alpha1
+k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=kyverno.io
+k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=kyverno.io
reports/v1
+k8s:openapi-gen=true +k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=reports.kyverno.io
+k8s:openapi-gen=true +k8s:deepcopy-gen=package +kubebuilder:object:generate=true +groupName=reports.kyverno.io
cmd
kyverno command
kyverno-init command
Cleans up stale webhookconfigurations created by kyverno that were not cleanedup
Cleans up stale webhookconfigurations created by kyverno that were not cleanedup
docs
perf-testing command
ext
hack
client-wrapper command
litmuschaos
pkg
client/clientset/versioned/fake
This package has the automatically generated fake clientset.
This package has the automatically generated fake clientset.
client/clientset/versioned/scheme
This package contains the scheme of the automatically generated clientset.
This package contains the scheme of the automatically generated clientset.
client/clientset/versioned/typed/kyverno/v1
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/kyverno/v1/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
client/clientset/versioned/typed/kyverno/v2
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/kyverno/v2/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
client/clientset/versioned/typed/kyverno/v2alpha1
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/kyverno/v2alpha1/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
client/clientset/versioned/typed/kyverno/v2beta1
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/kyverno/v2beta1/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
client/clientset/versioned/typed/policies.kyverno.io/v1beta1
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/policies.kyverno.io/v1beta1/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
client/clientset/versioned/typed/policyreport/v1alpha2
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/policyreport/v1alpha2/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
client/clientset/versioned/typed/reports/v1
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/reports/v1/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.
config/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
pss
tls
test

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL