Chapter 5. Kyverno

Run the test

make kyverno-install
make kyverno-apply
make kyverno-policy-test

This attempts to apply infra/k8s/bad/deploy-bad.yaml and saves the exact kubectl error output to artifacts/policy-tests.txt.

How to read the output

A typical rejection looks like:

Error from server: error when creating "deploy-bad.yaml":
admission webhook "validate.kyverno.svc" denied the request:

policy disallow-latest-tags, rule no-latest:
  validation error: Do not use :latest image tags.
  resource: Deployment/ship/bad-app, field: spec.template.spec.containers[0].image

policy enforce-pod-security-basics, rule require-seccontext:
  validation error: Harden containers: non-root, no privilege escalation, read-only root FS.
  resource: Deployment/ship/bad-app, field: spec.template.spec.containers[0].securityContext

Map the pieces:

  • policy → which file in policies/ matched
  • rule → rule name in that file
  • validation error → the message you wrote in the policy
  • resource → kind/namespace/name that failed
  • field → the exact path to fix

Evidence tip

Attach artifacts/policy-tests.txt to your PR (or include it in the evidence zip). Reviewers see which policy blocked which field and why.

Checklist

  • Bad manifest rejected
  • Evidence saved to artifacts/policy-tests.txt
  • You can point to the exact field to change