CNCF Accepts Kyverno as the Latest Sandbox Project
TL;DR
Nirmata, a Kubernetes operation and management platform, has announced that CNCF has accepted Kyverno, its Kubernetes-based policy engine, at the sandbox level. Kyverno is described on its official website as a policy engine designed for Kubernetes. With Kyverno, policies are managed as Kubernetes resources, and no new language is required to write policies.

Key Facts
Kyverno helps create policies and runs as a validating and mutating webhook aligned with the Kubernetes API server to provide configuration security.
It can mutate as well as generate resources, which allows users to do fine-grained configuration management, not possible manually.
Nirmata hopes that Kyverno can significantly increase the worldwide use of Kubernetes policy. Many people hesitate to implement Kubernetes policies due to their complexity.
In the future, Kyverno hopes to collaborate with other CNCF sandbox projects like cert-manager.
Details
Nirmata announced the news of the acceptance of Kyverno by CNCF in its official blog post. The post said that the decision to donate Kyverno was taken to promote the adoption of Kubernetes policies. Policy engines are crucial for enterprise Kubernetes management, but their complexity and learning curve hinder many from adopting it.
Kyverno comes with a host of features, including:
- Admission controls: To provide configuration security and block invalid and non-compliant configurations.
- Background scanning: Regularly scans all resources and creates a policy report for each namespace and cluster-wide resources.
- Automated rules for pod controllers: Uses pod policies to automatically generate rules for pod controllers, making Kubernetes policy management easier.
- Dynamic generation of new configurations: It helps enable several use cases by supporting flexible triggers for automatic dynamic regeneration of new configuration resources.
- Synchronize configuration across namespaces: Kyverno allows automatic propagation of changes from a common source by automatically synchronizing configuration changes across namespaces.
Security seems one of the main concerns of enterprises that have already adopted this Kubernetes. Several companies are building tools to resolve critical security issues in Kubernetes. Just like Kyverno helps in securing Kubernetes, there are several other tools like Kube-bench, Kube-hunter, and Project Calico that help in securing networking issues in Kubernetes.
To ensure compliance and apply best practices, policy engines are critical for enterprise Kubernetes management. The complexity and learning-curve of solutions that require a new language and foreign tools have hindered adoption. Kyverno simplifies Kubernetes policy management and allows admins to manage policies and reports as native resources.Jim BugwadiaCo-founder and CEO, Nirmata
Get similar news in your inbox weekly, for free
Share this news:
Latest stories
Best Cloud Hosting in the USA
This article explores five notable cloud hosting offers in the USA in a detailed way.
Best Dedicated Hosting in the USA
In this article, we explore 5 of the best dedicated hosting providers in the USA: …
The best tools for bare metal automation that people actually use
Bare metal automation turns slow, error-prone server installs into repeatable, API-driven workflows by combining provisioning, …
HIPAA and PCI DSS Hosting for SMBs: How to Choose the Right Provider
HIPAA protects patient data; PCI DSS protects payment data. Many small and mid-sized businesses now …
The Rise of GPUOps: Where Infrastructure Meets Thermodynamics
GPUs used to be a line item. Now they're the heartbeat of modern infrastructure.
Top Bare-Metal Hosting Providers in the USA
In a cloud-first world, certain workloads still require full control over hardware. High-performance computing, latency-sensitive …
Top 8 Cloud GPU Providers for AI and Machine Learning
As AI and machine learning workloads grow in complexity and scale, the need for powerful, …
How ManageEngine Applications Manager Can Help Overcome Challenges In Kubernetes Monitoring
We tested ManageEngine Applications Manager to monitor different Kubernetes clusters. This post shares our review …
AIOps with Site24x7: Maximizing Efficiency at an Affordable Cost
In this post we'll dive deep into integrating AIOps in your business suing Site24x7 to …
A Review of Zoho ManageEngine
Zoho Corp., formerly known as AdventNet Inc., has established itself as a major player in …












