Kyverno is a Kubernetes-native policy engine for defining and enforcing policy as code. Its stable policy types can validate, change, create, or delete resources, and check container image signatures and attestations. The Kyverno CLI can test policies against Kubernetes resource manifests in CI before they are applied to a live cluster. Documentation covers use with Helm, YAML manifests, GitHub Actions, and GitOps tools such as ArgoCD. Kyverno is installed inside a Kubernetes cluster; Helm is recommended for production, and YAML manifests are another option. A standard setup requires an admission controller, while background, reports, and cleanup controllers are optional. Production deployments should use high availability mode. Kyverno supports CEL-based policy types and describes extending Kubernetes-style policy use beyond Kubernetes as part of its mission. It is free and open source under Apache License 2.0, with CLI binaries listed for Linux, macOS, and Windows. The project is intended for platform engineering work involving security, compliance, automation, and governance.
Who it is for
Kyverno is aimed at platform engineering teams that want policy-based security, compliance, automation, or governance for Kubernetes. It also suits teams that test policy rules in CI before applying resources to a cluster.
What is good
- Validates, mutates, generates, and deletes resources
- Verifies container image signatures and attestations
- CLI tests policies against manifests in CI
- Works with Helm, GitHub Actions, and GitOps tools
- Free and open source
What to know first
- Requires installation in a Kubernetes cluster
- Production deployments should use high availability mode
- Fail-closed webhooks can block matching requests if unreachable
- Legacy policy types are scheduled for removal
Verdict
Kyverno combines in-cluster policy enforcement with CLI testing and several policy actions. Teams should account for its required admission controller, production availability guidance, and fail-closed webhook behavior.
Kyverno plans and pricing
All plansCompared on infrastructure policy as code tools
- Kubernetes security
- Yes
- Admission control
- Yes
- Deployment model
- self_hosted


