Kyverno Policy Exceptions
Enforce a security policy cluster-wide, then carve out a controlled, auditable exception for one legacy workload with a Kyverno PolicyException — the real-world answer to 'this one app can't comply yet.'
Your mission
A good security policy is cluster-wide and strict. Reality is messier: there's always one workload — a legacy app, a vendor image, a migration job — that can't comply yet. The wrong answers are to weaken the policy for everyone or to turn it off. The right answer is a narrow, explicit, auditable exception.
Kyverno's PolicyException does exactly that. It's a separate object that says
"these specific resources are exempt from this specific rule." The policy stays
strict for everything else; the exemption is a reviewable resource in Git, not a
hole punched in the policy itself.
You'll do two things:
- Enforce a real rule — every Pod in the
appsnamespace must run as non-root (securityContext.runAsNonRoot: true) — withvalidationFailureAction: Enforce, so violators are blocked at admission. - Exempt one workload — a
legacyapp that can't run as non-root — with aPolicyExceptionscoped to just it, so it's admitted while everything else stays protected.
The apps namespace is already created. Kyverno is installed and its exceptions
feature is enabled.
Useful aliases
In your terminal, k is aliased to kubectl and completion is configured. The
jumpbox also has k9s, jq and yq installed.