Kyverno is a policy engine for Kubernetes that enables you to define and enforce policies for your cluster resources. It provides a flexible and scalable solution for managing your cluster configuration, allowing you to enforce best practices, prevent misconfigurations, and enforce compliance requirements.
The kyverno/policies offer all kinds of security and best practice policies that you could use.
Install with:
helm repo add kyverno-charts oci://ghcr.io/kyverno/charts/
helm install kyverno kyverno-charts/kyverno -f values.yaml
See examples from other people.
Name | Repo | Stars | Version | Timestamp |
---|---|---|---|---|
kyverno | szinn/k8s-homelab | 121 | 3.1.4 | 6 hours ago |
kyverno | haraldkoch/kochhaus-home | 90 | 3.1.4 | 13 days ago |
kyverno | buroa/k8s-gitops | 123 | 3.1.4 | 17 days ago |
kyverno | rafaribe/home-ops | 34 | 3.1.4 | a month ago |
kyverno | Diaoul/home-ops | 57 | 3.1.4 | 2 months ago |
See the most popular values for this chart:
Key | Types |
---|---|
boolean | |
number | |
string | |
string | |
admissionController.rbac.clusterRole.extraResources[].verbs[] (32) - create | string |
boolean | |
string | |
string | |
string | |
number | |
admissionController.topologySpreadConstraints[].topologyKey (31) kubernetes.io/hostname | string |
string | |
string | |
string | |
string | |
number | |
number | |
admissionController.tolerations[].key (3) node-role.kubernetes.io/control-plane | string |
string | |
boolean | |
string | |
string | |
string | |
string | |
string | |
number | |
string | |
boolean | |
string | |
string | |
string | |
boolean | |
string | |
string | |
string | |
string | |
string | |
backgroundController.rbac.clusterRole.extraResources[].verbs[] (31) - create | string |
boolean | |
string | |
string | |
string | |
string | |
string | |
boolean | |
boolean | |
number | |
string | |
string | |
number | |
string | |
string | |
boolean | |
string | |
boolean | |
string | |
string | |
string | |
number | |
boolean | |
string | |
string | |
string | |
string | |
boolean | |
number | |
string | |
string | |
number | |
topologySpreadConstraints[].topologyKey (13) kubernetes.io/hostname | string |
topologySpreadConstraints[].whenUnsatisfiable (13) DoNotSchedule | string |
installCRDs (12) true | boolean |
boolean | |
string | |
number | |
number | |
updateStrategy.type (10) RollingUpdate | string |
config.webhooks[].objectSelector.matchExpressions[].key (6) webhooks.kyverno.io/exclude | string |
string | |
string | |
boolean | |
boolean | |
string | |
string | |
string | |
string | |
boolean | |
boolean | |
number | |
boolean | |
number | |
string | |
string | |
string | |
string | |
string | |
string |