Kyverno

Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.5

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

Kyverno is a Kubernetes-native policy engine for defining and enforcing policy as code. Its stable policy types can validate, change, create, or delete resources, and check container image signatures and attestations. The Kyverno CLI can test policies against Kubernetes resource manifests in CI before they are applied to a live cluster. Documentation covers use with Helm, YAML manifests, GitHub Actions, and GitOps tools such as ArgoCD. Kyverno is installed inside a Kubernetes cluster; Helm is recommended for production, and YAML manifests are another option. A standard setup requires an admission controller, while background, reports, and cleanup controllers are optional. Production deployments should use high availability mode. Kyverno supports CEL-based policy types and describes extending Kubernetes-style policy use beyond Kubernetes as part of its mission. It is free and open source under Apache License 2.0, with CLI binaries listed for Linux, macOS, and Windows. The project is intended for platform engineering work involving security, compliance, automation, and governance.

Who it is for

Kyverno is aimed at platform engineering teams that want policy-based security, compliance, automation, or governance for Kubernetes. It also suits teams that test policy rules in CI before applying resources to a cluster.

What is good

  • Validates, mutates, generates, and deletes resources
  • Verifies container image signatures and attestations
  • CLI tests policies against manifests in CI
  • Works with Helm, GitHub Actions, and GitOps tools
  • Free and open source

What to know first

  • Requires installation in a Kubernetes cluster
  • Production deployments should use high availability mode
  • Fail-closed webhooks can block matching requests if unreachable
  • Legacy policy types are scheduled for removal

Verdict

Kyverno combines in-cluster policy enforcement with CLI testing and several policy actions. Teams should account for its required admission controller, production availability guidance, and fail-closed webhook behavior.

Kyverno plans and pricing

All plans
Kyverno Free Open-source project · Apache License 2.0 github.com · 4 Oct 2026

Compared on infrastructure policy as code tools

Kubernetes security
Yes
Admission control
Yes
Deployment model
self_hosted

Best Kyverno alternatives

See all 12