Kyverno is a policy engine for Kubernetes that enables you to define and enforce policies for your cluster resources. It provides a flexible and scalable solution for managing your cluster configuration, allowing you to enforce best practices, prevent misconfigurations, and enforce compliance requirements.
The kyverno/policies offer all kinds of security and best practice policies that you could use.
Install with:
helm repo add kyverno oci://ghcr.io/kyverno/charts/
helm install kyverno kyverno/kyverno -f values.yamlSee examples from other people.
| Name | Repo | Stars | Version | Timestamp |
|---|---|---|---|---|
| kyverno | xunholy/k8s-gitops | 477 | 3.2.2 | 13 days ago |
| kyverno | axeII/home-ops | 41 | 3.2.6 | 19 days ago |
| kyverno | ishioni/homelab-ops | 94 | 3.2.6 | a month ago |
| kyverno | haraldkoch/kochhaus-home | 109 | 3.2.6 | 2 months ago |
| kyverno | budimanjojo/home-cluster | 160 | 3.2.6 | 2 months ago |
See the most popular values for this chart:
| Key | Types |
|---|---|
| boolean | |
| string | |
| boolean | |
| number | |
| boolean | |
| boolean | |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| string | |
| boolean | |
| number | |
| number | |
| boolean | |
| string | |
| string | |
| string | |
admissionController.rbac.clusterRole.extraResources[].verbs[] (30) - create | string |
| string | |
| string | |
| number | |
admissionController.topologySpreadConstraints[].topologyKey (30) kubernetes.io/hostname | string |
| string | |
| string | |
| string | |
| string | |
| number | |
| number | |
| string | |
| string | |
| number | |
| string | |
| boolean | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| string | |
| string | |
backgroundController.rbac.clusterRole.extraResources[].verbs[] (29) - create | string |
| string | |
| string | |
| string | |
| string | |
| boolean | |
| boolean | |
| number | |
| string | |
| string | |
| number | |
| string | |
| string | |
installCRDs (11) true | boolean |
| boolean | |
| string | |
| string | |
| number | |
topologySpreadConstraints[].topologyKey (11) kubernetes.io/hostname | string |
topologySpreadConstraints[].whenUnsatisfiable (11) DoNotSchedule | string |
| number | |
| number | |
updateStrategy.type (8) RollingUpdate | string |
config.webhooks[].objectSelector.matchExpressions[].key (5) webhooks.kyverno.io/exclude | string |
| string | |
| string | |
| boolean | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
| boolean | |
| number | |
| boolean | |
| number | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| string | |
| boolean |