
Kubernetes Policies And Governance - Ask Me Anything With Jim Bugwadia
Source: YouTube · DevOps & AI Toolkit · published Nov 11, 2022 · 57:08
Jim Bugwadia discusses Kyverno, a Kubernetes-native policy engine that simplifies governance by using YAML instead of Rego, enabling security enforcement and automation within the cluster 2:20-4:50.
Key Takeaways:
• Kyverno differentiates itself from OPA by allowing users to write policies as standard Kubernetes resources, eliminating the need to learn the Rego language and leveraging existing YAML knowledge 2:20-3:50.
• The engine is deeply integrated with Kubernetes, utilizing CRDs and OpenAPI schemas to apply policies to both built-in resources and Custom Resource Definitions (CRDs) effectively 5:02-6:49.
• Operating within the admission control phase, Kyverno can validate or mutate API requests to ensure compliance and automate resource generation 8:48-12:02.
• Upcoming releases, such as version 1.9, will decouple policy exceptions from the policies themselves to improve management and flexibility for enterprises 26:45-29:46.
• Policies serve as a "digital contract" between DevOps and Security teams, facilitating automated compliance reporting without requiring deep security involvement in daily operations 47:55-49:54.
The session underscores the shift towards Kubernetes-specific policy tools that prioritize native integration and ease of use over general-purpose solutions.
Sources:
- 2:20-4:50 Discussion on Kyverno vs OPA and the benefits of YAML policies
- 5:02-6:49 Explanation of Kubernetes-native integration and CRD support
- 8:48-12:02 Overview of admission controllers a
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
okay thank you so much for joining everybody this is yet another ask us anything because we have a special guest but before I introduce the guest uh start preparing your questions stop start typing the question that's the only thing we do we answer questions there is nothing else going on and the topic today is around policies governance kubernetes policies and governance uh and our guest is Jim from nirmata uh the company behind uh caverno my one of my favorite projects so uh you wanna they want to introduce yourself Jim of course um thank you Victor and thanks everyone for joining I'm Jim beguardia co-founder at nermata and like Victor mentioned we are the company that created caverno which is a kubernetes you know policy engine I also co-chair in the policy working group within the kube…