Kyverno
Kyverno states policy as Kubernetes resources: validate, mutate, generate and verifyImages rules, plus PolicyExceptions, background scans and reports. Interviewers want a rule you could write.
on this pageshowhide
explore
- Matching and Deciding25 questions
- ClusterPolicy and Rules4 questions
- Pattern Anchors4 questions
- Conditions and Expressions4 questions
- Pod Controller Autogen4 questions
- Image Attestor Rules5 questions
- Context and Substitution4 questions
- Changing and Creating8 questions
- Mutation Patches4 questions
- Generate and Cleanup4 questions
- When It Does Not Block8 questions
- Dry Runs and Reports4 questions
- PolicyException Objects4 questions
questions
page 2 of 2When do you split Kyverno rules across separate policies instead of one ClusterPolicy?
basics
~20 sSplit when rules have different owners, review paths or lifecycles, because the policy object is the unit of creation, deletion and RBAC. Do not split merely to give rules different failure actions — that is already per-rule.
Your Kyverno verifyImages rule gates scan freshness — what can it prove to an auditor about workloads already running?
basics
~10 sOnly that workloads admitted after the rule went live met the condition at that moment. It says nothing about pods admitted earlier, whether attestations are still fresh, or images no pattern selected.
How do you scope a Kyverno PolicyException to one vendor workload, not its whole namespace?
basics
~20 sCombine namespaces, kinds and a label selector in the exception's match block, and list the exact rule names. Avoid matching on pod names, which carry generated suffixes, and avoid a namespace-only match, which silently covers every future workload there.
How does a Kyverno cleanup policy remove completed Jobs, and when do you use a TTL label instead?
basics
~20 sA Kyverno ClusterCleanupPolicy matches a kind, narrows it with conditions such as a succeeded status, and carries a cron schedule; the cleanup controller deletes every match on each tick. A cleanup.kyverno.io/ttl label instead expires one specific object.
Kyverno refuses your Deployment with two near-identical messages - what causes the duplication?
basics
~20 sTwo rules matched the same object: the rule Kyverno derived from a Pod rule for Deployments, and a separately maintained rule that matches Deployment directly. Kyverno reports every failing rule, so the same control is stated twice.
In a Kyverno verifyImages rule, how do you require signatures from two of three named attestors?
basics
~20 sPut the three attestors as entries in one attestors set and give that set count: 2. Inside a set, count is a threshold over entries; omitting it requires all of them. Separate sets are ANDed.
A PersistentVolumeClaim has a backup annotation nobody wrote. How do you confirm Kyverno added it?
basics
~20 sRead the object's policies.kyverno.io/last-applied-patches annotation, which records the patch and the policy and rule that applied it. Corroborate with events on the resource, the policy report entry, and a Kyverno CLI replay of the policy.
Kyverno reports show thousands of failing resources that no team has fixed in months. What do you do?
basics
~20 sTreat the count as a symptom, not a work queue. Break it down by rule and by owning team, delete or narrow rules nobody will ever act on, and tie what remains to a dated, per-team list.
Which Kyverno validate form do you standardise on when dozens of teams will patch the policy?
basics
~20 sChoose on reviewability, not expressiveness. Make the declarative pattern the default because governed teams can read it, allow deny conditions where operators or request fields are genuinely needed, and reserve the CEL form for teams already fluent in it.
Your Kyverno allow lists live in ConfigMaps - who should be able to change them, and how?
basics
~20 sUpdate rights on that ConfigMap are equivalent to amending the policy, so govern it like policy: platform-owned namespace, the same repository and review as the rule, alerting on writes, and a pre-agreed emergency path that is reconciled back into git.
Should tenants own Kyverno Policy objects in their own namespaces on a shared cluster?
basics
~20 sUsually yes, with limits. A namespaced Kyverno Policy can only add constraints inside its own namespace and cannot relax a platform ClusterPolicy, so the security downside is small. The real cost is operational: tenants can block themselves.
showing 31–41 of 41