All learning paths

YOUR LEARNING PATH

KCA: Kyverno Policy

The Kyverno Certified Associate core: write policy-as-code that validates, mutates and generates Kubernetes resources at admission — on a real cluster with Kyverno enforcing.

0 / 7 complete0%

Your practice sequence

One exercise at a time
  1. Validating Pods with Kyverno

    Write a Kyverno validate policy that enforces a required label, then watch it block a non-compliant workload at admission.

    IntermediatePlus30 minLocked
  2. Mutating Pods with Kyverno

    Write a Kyverno policy that injects a team label into every Pod.

    IntermediatePlus35 minLocked
  3. Generating Resources with Kyverno

    Write a Kyverno generate policy that auto-provisions a default ConfigMap into every new team namespace — infrastructure that creates itself.

    IntermediatePlus30 minLocked
  4. Block Unpinned Images

    Supply-chain hygiene at admission: write a Kyverno policy that rejects the mutable :latest tag so every workload must pin an explicit image version, then prove it admits a pinned image and blocks :latest.

    IntermediatePlus30 minLocked
  5. Challenge

    Validate, Mutate, Generate

    An exam-pace Kyverno drill fusing all three core policy types in one pass: a validate policy that enforces a label, a mutate policy that injects one, and a generate policy that seeds a resource into new namespaces — each proven live.

    AdvancedPlus35 minLocked

Test yourself

Mock Exam

Timed, scored under exam conditions. Take these once the tree feels solid.

KCA Mock Exam — Core

60 min · Pro

Locked
KCA — Beyond ExamBeyond Exam

45 min · Pro

Locked