Kyverno Mutation with JSON Patches
Mutate with a surgeon's precision using RFC 6902 JSON patches: add a label, then add an annotation whose key contains a slash — meeting the two gotchas that trip everyone, the ~1 escape and the parent object that must exist first.
Your mission
Kyverno mutates in two styles. patchStrategicMerge is the friendly one — you write
a fragment of the resource and Kyverno merges it in. patchesJson6902 is the precise
one: a list of RFC 6902 JSON Patch operations — add, replace, remove,
move, copy, test — each targeting an exact location by JSON Pointer path.
You reach for it when you need surgical control: touch one array element, remove a
field, or add a key whose name a merge can't express cleanly.
Two gotchas trip everyone, and this lab walks you straight into both:
- The
~1escape. In a JSON Pointer,/separates path segments. So a key that itself contains a/— like the labelexample.com/team— must be written with/escaped as~1:/metadata/labels/example.com~1team. (And a literal~is~0.) Miss it and the op walks into the wrong place. - The parent must exist.
addto/metadata/annotations/foofails if/metadata/annotationsdoesn't exist yet —addcreates a key in an object, not the object itself.
In this lab you add a plain label with a JSON patch, then add a label whose key contains a slash — meeting the escape head-on.
The apps namespace is already created; Kyverno is installed.
Useful aliases
In your terminal, k is aliased to kubectl and completion is configured. The
jumpbox also has k9s, jq and yq installed.