Chapter 8. Kyverno and Kubernetes
Kyverno, Greek for govern, is a mature OSS—incubating CNCF—policy-engine project that is designed specifically for Kubernetes. With Kyverno, you can policy-enable your Kubernetes clusters and DevOps pipelines to control cluster behavior and validate policies before use. As we will see in this chapter, Kyverno integrates to Kubernetes via the same dynamic admission controllers, similar to previous Kubernetes solutions that we have already explored and that we will see in subsequent chapters.
The Kyverno project, created by Nirmata, enjoys a very active community of contributors and users. The following links will help you gain more information about Kyverno:
Unlike the Kubernetes PaC solutions that we have discussed so far, Kyverno is not underpinned by OPA or Rego. Kyverno policies are written using YAML. YAML syntax is used widely throughout Kubernetes, so Kyverno adoption does not require learning a new policy-language syntax. The learning curve for Kyverno includes the Kyverno YAML lexicon. As we will see later in this chapter, an additional JSON query language—JMESPath—can be used to apply fine-grained selection logic in Kyverno policies.
Let’s get started by installing Kyverno in minikube.
Installation
Kyverno can be installed using Helm or via kubectl and YAML resources. As a Kyverno user, I prefer the Helm install. The Helm chart ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access