Validating Pods with Kyverno
Write a Kyverno validate policy that enforces a required label, then watch it block a non-compliant workload at admission.
Your mission
Mutation adds things to resources; validation decides whether a resource is
allowed at all. A Kyverno validate policy inspects incoming objects at
admission and, in Enforce mode, rejects the ones that break your rules —
before they ever exist in the cluster. It's how you make a standard mandatory:
"every Pod must declare an owning team," "no :latest images," "resources
limits are required."
A validate rule has two moving parts: a match (which resources it applies to)
and a pattern (the shape a resource must have). Kyverno supports two failure
actions — Audit (log a violation, allow it) and Enforce (block it). The gap
between them is the whole game: an Audit policy that everyone ignores is not a
control.
In this lab you write a policy that requires a team label on Pods in the demo
namespace, set it to Enforce, and then prove it by deploying one workload that
complies and watching a non-compliant one get rejected.
Useful aliases
k is aliased to kubectl and completion is configured. The jumpbox also has
k9s, jq and yq. Kyverno is already installed and ready.