KCA — Beyond Exam
The hardest Kyverno tier: a multi-rule guardrail policy that enforces four constraints at once, a mutate policy that injects several defaults, and a generate policy that seeds two resources per namespace — stricter than the exam or killer.sh. Pass mark 75%.
Your mission
The hardest Kyverno tier, above the drill and simulator. Three tasks, each denser
than a single-policy question: a multi-rule guardrail policy that enforces four
constraints at once, a mutate policy that injects several defaults, and a generate
policy that seeds two resources per namespace. Pass mark 75%; hints locked
while it runs. Kyverno is installed; work in apps.
Note the interaction: once Task 1 enforces its guardrails, everything you create in
apps — including Task 2's proof Pod — must satisfy all four rules.
kubectl config set-context --current --namespace=apps