Generating Resources with Kyverno
Write a Kyverno generate policy that auto-provisions a default ConfigMap into every new team namespace — infrastructure that creates itself.
Your mission
Validate policies say no; mutate policies edit; generate policies create. A Kyverno generate rule watches for a trigger — a new Namespace, a new ServiceAccount, a Deployment — and provisions companion resources automatically. It's how platform teams guarantee that every namespace starts life with the defaults it needs: a NetworkPolicy, a ResourceQuota, a pull-secret, a baseline ConfigMap — without anyone remembering to add them.
The rule names a trigger (via match) and a target (via generate). Kyverno
fills in the target's namespace and fields from the trigger using variables like
{{request.object.metadata.name}}. With synchronize: true, the generated
resource is kept in step with the policy and restored if someone deletes it.
In this lab you write a policy that drops a default-settings ConfigMap into
every namespace labelled for it, then create a namespace and watch the ConfigMap
appear on its own.
Useful aliases
k is aliased to kubectl and completion is configured. The jumpbox also has
k9s, jq and yq. Kyverno is already installed and ready.