Back to Practice
Lab

Kyverno Policy Exceptions

Enforce a security policy cluster-wide, then carve out a controlled, auditable exception for one legacy workload with a Kyverno PolicyException — the real-world answer to 'this one app can't comply yet.'

Your mission

A good security policy is cluster-wide and strict. Reality is messier: there's always one workload — a legacy app, a vendor image, a migration job — that can't comply yet. The wrong answers are to weaken the policy for everyone or to turn it off. The right answer is a narrow, explicit, auditable exception.

Kyverno's PolicyException does exactly that. It's a separate object that says "these specific resources are exempt from this specific rule." The policy stays strict for everything else; the exemption is a reviewable resource in Git, not a hole punched in the policy itself.

You'll do two things:

  1. Enforce a real rule — every Pod in the apps namespace must run as non-root (securityContext.runAsNonRoot: true) — with validationFailureAction: Enforce, so violators are blocked at admission.
  2. Exempt one workload — a legacy app that can't run as non-root — with a PolicyException scoped to just it, so it's admitted while everything else stays protected.

The apps namespace is already created. Kyverno is installed and its exceptions feature is enabled.

Useful aliases

In your terminal, k is aliased to kubectl and completion is configured. The jumpbox also has k9s, jq and yq installed.

Skills you'll put into practice

kyvernopolicyadmission-controlexceptionskca

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation