Kyverno Rollout: Audit, Then Enforce
Ship a policy the safe way: run it in Audit first, so violations are reported in a PolicyReport without blocking anyone, then flip it to Enforce once the fleet is clean. The professional rollout every team uses.
Your mission
You've written a policy. Turning it straight to Enforce on a live cluster is how
you cause an outage — the first non-compliant Deployment anyone rolls out is
suddenly rejected, and it might be theirs at 2am. The professional way to ship a
policy is a two-phase rollout, and Kyverno builds it in with one field:
validationFailureAction.
Audit— the policy evaluates every resource and records violations in a PolicyReport, but admits everything. Nothing breaks. You get a list of who's non-compliant, so you can fix them (or grant exceptions) first.Enforce— once the fleet is clean, flip the same policy to block. Now new violations are rejected at admission.
The field is mutable, so the rollout is literally: apply in Audit, read the
report, fix violators, change one word to Enforce.
In this lab you run a require an owner label policy in Audit (watching it admit a
non-compliant app while reporting it), then promote it to Enforce.
The apps namespace is already created; Kyverno is installed.
Useful aliases
In your terminal, k is aliased to kubectl and completion is configured. The
jumpbox also has k9s, jq and yq installed.