YOUR LEARNING PATH
KCA: Kyverno Policy
The Kyverno Certified Associate core: write policy-as-code that validates, mutates and generates Kubernetes resources at admission — on a real cluster with Kyverno enforcing.
Your practice sequence
One exercise at a timeValidating Pods with Kyverno
Write a Kyverno validate policy that enforces a required label, then watch it block a non-compliant workload at admission.
IntermediatePlus30 minLockedMutating Pods with Kyverno
Write a Kyverno policy that injects a team label into every Pod.
IntermediatePlus35 minLockedGenerating Resources with Kyverno
Write a Kyverno generate policy that auto-provisions a default ConfigMap into every new team namespace — infrastructure that creates itself.
IntermediatePlus30 minLockedBlock Unpinned Images
Supply-chain hygiene at admission: write a Kyverno policy that rejects the mutable :latest tag so every workload must pin an explicit image version, then prove it admits a pinned image and blocks :latest.
IntermediatePlus30 minLocked- Challenge
Validate, Mutate, Generate
An exam-pace Kyverno drill fusing all three core policy types in one pass: a validate policy that enforces a label, a mutate policy that injects one, and a generate policy that seeds a resource into new namespaces — each proven live.
AdvancedPlus35 minLocked
Test yourself
Mock ExamTimed, scored under exam conditions. Take these once the tree feels solid.
60 min · Pro
45 min · Pro