Kyverno (Issue #016) can enforce this at admission.
Reject CNPG Cluster resources that don't have a properly-sized PDB + zone anti-affinity. One policy, half the quorum-PDB mistakes prevented at deploy time.
Governance earning its keep on stateful workloads.
https://t.co/4RV4VRDqPU 🛡️
Jim Bugwadia on why finding a Kubernetes problem is only half the battle for Kyverno users https://t.co/SqhamaQExr - Explore Kyverno's journey to CNCF graduation, a pivotal to...
@dthn_io The built-in types are great for simpler policies at admission. You still need Kyverno (or OPA) for complex policies, API lookups, reporting, testing, and applying to existing resources. Kyverno can now auto-generate K8s policy types where possible. (I am a maintainer).
Kube GitOps Lab 02 is live: Kyverno admission control via ArgoCD on a single-node k3s cluster.
Covers sync waves, ignoreDifferences gotchas, 4 baseline ClusterPolicies, and the Audit -> Enforce lifecycle.
https://t.co/ojQqa4p139
#Kubernetes#GitOps#DevOps#Kyverno
Full #Observability for #Kyverno With #ObservabilityasCode
The adoption of Kyverno solves the challenge of #PolicyasCode. However, a new question emerges for platform engineers: what happens when a slow policy rule adds latency? A slow admission webhook can degrade performance across the #Kubernetes cluster.
https://t.co/fCkjksxt7e
🚨 The #KyvernoCon Virtual schedule is LIVE!
Join us May 8 for real-world talks on: ✔️ Policy as Code
✔️ Platform Engineering
✔️ Security + AI governance
🎤 Speakers from across the Kyverno ecosystem
🌍 Built for our global community
👉 Register now:
https://t.co/E75wqMUlYk
AI agents come in several different forms. Here is a simple classification we have been using internally. This can be useful for both builders and end users, who need to govern agents. How do you categorize agents?
https://t.co/DRJm3sQn5A
Giving devs self-service infra without guardrails is like giving them root.
Here's how to prevent $10K RDS instances with one Kyverno policy.
https://t.co/583O1pgl5r
Generate: when a dev creates a DatabaseClaim, Kyverno can auto-create a matching BackupPolicy resource.
No manual step. No Jira ticket. The policy ensures every database gets backups. Zero human intervention.
Self-service doesn't mean no rules. It means the rules are automated.
Kyverno validates. Crossplane provisions. Secrets flow to pods. Devs get databases in minutes. Platform team sleeps.
Full guide with policy examples:
https://t.co/583O1pgl5r 🛠️
🚀 Kyverno graduates from CNCF after demonstrating production readiness & strong adoption! Simplify policy enforcement in Kubernetes & cloud native environments. #CNCF#CloudNative#Kyverno
https://t.co/WobGBybl2e
Looking forward to presenting today at KubeCon EU in Amsterdam, on how Kyverno policy as code enables automated compliance at scale!
https://t.co/W0Ftlp3fNv