skip to content

Kyverno

Kyverno states policy as Kubernetes resources: validate, mutate, generate and verifyImages rules, plus PolicyExceptions, background scans and reports. Interviewers want a rule you could write.

on this pageshow

explore

questions

page 2 of 2

When do you split Kyverno rules across separate policies instead of one ClusterPolicy?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Split when rules have different owners, review paths or lifecycles, because the policy object is the unit of creation, deletion and RBAC. Do not split merely to give rules different failure actions — that is already per-rule.

open as a page

Your Kyverno verifyImages rule gates scan freshness — what can it prove to an auditor about workloads already running?

level: principalimportance: should knowfreq 30%

basics

~10 s

Only that workloads admitted after the rule went live met the condition at that moment. It says nothing about pods admitted earlier, whether attestations are still fresh, or images no pattern selected.

open as a page

How do you scope a Kyverno PolicyException to one vendor workload, not its whole namespace?

level: middleimportance: nice to knowfreq 36%

basics

~20 s

Combine namespaces, kinds and a label selector in the exception's match block, and list the exact rule names. Avoid matching on pod names, which carry generated suffixes, and avoid a namespace-only match, which silently covers every future workload there.

open as a page

How does a Kyverno cleanup policy remove completed Jobs, and when do you use a TTL label instead?

level: middleimportance: nice to knowfreq 31%

basics

~20 s

A Kyverno ClusterCleanupPolicy matches a kind, narrows it with conditions such as a succeeded status, and carries a cron schedule; the cleanup controller deletes every match on each tick. A cleanup.kyverno.io/ttl label instead expires one specific object.

open as a page

Kyverno refuses your Deployment with two near-identical messages - what causes the duplication?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

Two rules matched the same object: the rule Kyverno derived from a Pod rule for Deployments, and a separately maintained rule that matches Deployment directly. Kyverno reports every failing rule, so the same control is stated twice.

open as a page

In a Kyverno verifyImages rule, how do you require signatures from two of three named attestors?

level: middleimportance: nice to knowfreq 42%

basics

~20 s

Put the three attestors as entries in one attestors set and give that set count: 2. Inside a set, count is a threshold over entries; omitting it requires all of them. Separate sets are ANDed.

open as a page

A PersistentVolumeClaim has a backup annotation nobody wrote. How do you confirm Kyverno added it?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

Read the object's policies.kyverno.io/last-applied-patches annotation, which records the patch and the policy and rule that applied it. Corroborate with events on the resource, the policy report entry, and a Kyverno CLI replay of the policy.

open as a page

Kyverno reports show thousands of failing resources that no team has fixed in months. What do you do?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Treat the count as a symptom, not a work queue. Break it down by rule and by owning team, delete or narrow rules nobody will ever act on, and tie what remains to a dated, per-team list.

open as a page

Which Kyverno validate form do you standardise on when dozens of teams will patch the policy?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Choose on reviewability, not expressiveness. Make the declarative pattern the default because governed teams can read it, allow deny conditions where operators or request fields are genuinely needed, and reserve the CEL form for teams already fluent in it.

open as a page

Your Kyverno allow lists live in ConfigMaps - who should be able to change them, and how?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Update rights on that ConfigMap are equivalent to amending the policy, so govern it like policy: platform-owned namespace, the same repository and review as the rule, alerting on writes, and a pre-agreed emergency path that is reconciled back into git.

open as a page

Should tenants own Kyverno Policy objects in their own namespaces on a shared cluster?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Usually yes, with limits. A namespaced Kyverno Policy can only add constraints inside its own namespace and cannot relax a platform ClusterPolicy, so the security downside is small. The real cost is operational: tenants can block themselves.

open as a page

showing 31–41 of 41