Back to Practice
Lab

Generating Resources with Kyverno

Write a Kyverno generate policy that auto-provisions a default ConfigMap into every new team namespace — infrastructure that creates itself.

Your mission

Validate policies say no; mutate policies edit; generate policies create. A Kyverno generate rule watches for a trigger — a new Namespace, a new ServiceAccount, a Deployment — and provisions companion resources automatically. It's how platform teams guarantee that every namespace starts life with the defaults it needs: a NetworkPolicy, a ResourceQuota, a pull-secret, a baseline ConfigMap — without anyone remembering to add them.

The rule names a trigger (via match) and a target (via generate). Kyverno fills in the target's namespace and fields from the trigger using variables like {{request.object.metadata.name}}. With synchronize: true, the generated resource is kept in step with the policy and restored if someone deletes it.

In this lab you write a policy that drops a default-settings ConfigMap into every namespace labelled for it, then create a namespace and watch the ConfigMap appear on its own.

Useful aliases

k is aliased to kubectl and completion is configured. The jumpbox also has k9s, jq and yq. Kyverno is already installed and ready.

Skills you'll put into practice

kyvernopolicyautomation

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation