Project reference ↗

Gatekeeper checks whether Kubernetes resources meet rules set by a platform team. For example, a team can require particular configuration before accepting a new workload, while audits identify violations among resources already present. It uses Open Policy Agent to evaluate reusable policy definitions. This is useful when shared cluster requirements need consistent enforcement, but rejecting new changes and reporting existing violations are different actions that must be configured deliberately.

Chart ownership

The upstream open-policy-agent/gatekeeper project publishes the gatekeeper chart through https://open-policy-agent.github.io/gatekeeper/charts. Installing this chart does not translate a legacy standalone OPA deployment's policies automatically.

Before adoption

Test representative allowed and denied resources before enforcing constraints. Decide webhook timeout and failure behavior, protect exemption labels, and preserve a way to repair restrictive policies. Review chart hooks and CRD changes for upgrades. The installation documentation warns that deleting Gatekeeper CRDs also deletes constraint templates, constraints and configuration; keep those definitions under version control and avoid treating CRD removal as routine cleanup.

Start with the installation documentation and the upstream chart reference.

Sources & further reading

  1. Gatekeeper installation
  2. Gatekeeper chart source

Spotted something that needs another look?

Help improve this page →