Back to Practice
Lab

Kyverno Mutation with JSON Patches

Mutate with a surgeon's precision using RFC 6902 JSON patches: add a label, then add an annotation whose key contains a slash — meeting the two gotchas that trip everyone, the ~1 escape and the parent object that must exist first.

Your mission

Kyverno mutates in two styles. patchStrategicMerge is the friendly one — you write a fragment of the resource and Kyverno merges it in. patchesJson6902 is the precise one: a list of RFC 6902 JSON Patch operations — add, replace, remove, move, copy, test — each targeting an exact location by JSON Pointer path. You reach for it when you need surgical control: touch one array element, remove a field, or add a key whose name a merge can't express cleanly.

Two gotchas trip everyone, and this lab walks you straight into both:

  • The ~1 escape. In a JSON Pointer, / separates path segments. So a key that itself contains a / — like the label example.com/team — must be written with / escaped as ~1: /metadata/labels/example.com~1team. (And a literal ~ is ~0.) Miss it and the op walks into the wrong place.
  • The parent must exist. add to /metadata/annotations/foo fails if /metadata/annotations doesn't exist yet — add creates a key in an object, not the object itself.

In this lab you add a plain label with a JSON patch, then add a label whose key contains a slash — meeting the escape head-on.

The apps namespace is already created; Kyverno is installed.

Useful aliases

In your terminal, k is aliased to kubectl and completion is configured. The jumpbox also has k9s, jq and yq installed.

Skills you'll put into practice

kyvernopolicymutationkca

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation