Back to Practice
Lab

Validating Pods with Kyverno

Write a Kyverno validate policy that enforces a required label, then watch it block a non-compliant workload at admission.

Your mission

Mutation adds things to resources; validation decides whether a resource is allowed at all. A Kyverno validate policy inspects incoming objects at admission and, in Enforce mode, rejects the ones that break your rules — before they ever exist in the cluster. It's how you make a standard mandatory: "every Pod must declare an owning team," "no :latest images," "resources limits are required."

A validate rule has two moving parts: a match (which resources it applies to) and a pattern (the shape a resource must have). Kyverno supports two failure actions — Audit (log a violation, allow it) and Enforce (block it). The gap between them is the whole game: an Audit policy that everyone ignores is not a control.

In this lab you write a policy that requires a team label on Pods in the demo namespace, set it to Enforce, and then prove it by deploying one workload that complies and watching a non-compliant one get rejected.

Useful aliases

k is aliased to kubectl and completion is configured. The jumpbox also has k9s, jq and yq. Kyverno is already installed and ready.

Skills you'll put into practice

kyvernopolicyadmission-control

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation