Project reference ↗

When many teams deploy to one cluster, rules such as using approved images are hard to enforce through code review alone. Kyverno checks Kubernetes resource changes against centrally defined rules and can report violations or reject a request. It can also verify image signatures, helping a team require artifacts from an approved build identity. The policy design still needs clear exceptions and a plan for what happens when verification is unavailable.

Start with a narrow policy

Choose one concrete rule, such as requiring an approved image identity, and document the exceptions. Use the policy API and verification syntax for the installed release. The current documentation marks ClusterPolicy as deprecated and maps its verifyImages rules to CEL-based ImageValidatingPolicy. Follow the release-specific migration guidance before replacing existing policies; the APIs and examples are not interchangeable.

Enforcement is an availability decision

Test the effect of an unavailable verifier, registry or webhook before blocking production admissions. Include controller-generated workloads, emergency tooling, system namespaces and upgrades. Decide who can authorize exceptions and how they expire. An image signature establishes the chosen identity claim; it does not prove an image has no vulnerabilities.

The image-signing guide explains how to connect build identity, verification and admission policy without confusing their responsibilities.

Sources & further reading

  1. Kyverno installation
  2. ClusterPolicy image verification (legacy API)
  3. ImageValidatingPolicy
  4. CEL policy migration and deprecation schedule

Spotted something that needs another look?

Help improve this page →