Back to Practice
Lab

Kyverno Rollout: Audit, Then Enforce

Ship a policy the safe way: run it in Audit first, so violations are reported in a PolicyReport without blocking anyone, then flip it to Enforce once the fleet is clean. The professional rollout every team uses.

Your mission

You've written a policy. Turning it straight to Enforce on a live cluster is how you cause an outage — the first non-compliant Deployment anyone rolls out is suddenly rejected, and it might be theirs at 2am. The professional way to ship a policy is a two-phase rollout, and Kyverno builds it in with one field: validationFailureAction.

  • Audit — the policy evaluates every resource and records violations in a PolicyReport, but admits everything. Nothing breaks. You get a list of who's non-compliant, so you can fix them (or grant exceptions) first.
  • Enforce — once the fleet is clean, flip the same policy to block. Now new violations are rejected at admission.

The field is mutable, so the rollout is literally: apply in Audit, read the report, fix violators, change one word to Enforce.

In this lab you run a require an owner label policy in Audit (watching it admit a non-compliant app while reporting it), then promote it to Enforce.

The apps namespace is already created; Kyverno is installed.

Useful aliases

In your terminal, k is aliased to kubectl and completion is configured. The jumpbox also has k9s, jq and yq installed.

Skills you'll put into practice

kyvernopolicyadmission-controlreportingkca

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation