🎯 MỤC TIÊU BÀI HỌC
- ✅ Kyverno architecture và admission webhook
- ✅ Validation policies (block dangerous configs)
- ✅ Mutation policies (inject defaults)
- ✅ Generation policies (auto-create resources)
- ✅ Image verification (cosign signatures)
- ✅ Policy-as-code GitOps workflow
PHẦN 1: KYVERNO ARCHITECTURE
Kyverno Flow:
kubectl apply
│
▼
┌──────────┐ ┌──────────────────┐
│API Server│───►│ Kyverno Webhook │
│ │ │ (Admission) │
│ │ │ │
│ │◄───│ Allow / Deny / │
│ │ │ Mutate resource │
└──────────┘ └──────────────────┘
│
┌───────┴────────┐
│ Policies │
│ - Validate │
│ - Mutate │
│ - Generate │
│ - VerifyImages │
└────────────────┘
# Install Kyverno:
helm repo add kyverno https://kyverno.github.io/kyverno/
helm repo update
helm install kyverno kyverno/kyverno \
--namespace kyverno \
--create-namespace \
-f kyverno-values.yaml
# kyverno-values.yaml:
admissionController:
replicas: 3
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
backgroundController:
replicas: 2
cleanupController:
replicas: 2
reportsController:
replicas: 2
PHẦN 2: VALIDATION POLICIES
# Require resource limits:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-resource-limits
spec:
validationFailureAction: Enforce
background: true
rules:
- name: validate-limits
match:
any:
- resources:
kinds: ["Pod"]
exclude:
any:
- resources:
namespaces: ["kube-system", "kyverno"]
validate:
message: "CPU and memory limits are required"
pattern:
spec:
containers:
- resources:
limits:
memory: "?*"
cpu: "?*"
---
# Disallow privileged containers:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: disallow-privileged
spec:
validationFailureAction: Enforce
rules:
- name: deny-privileged
match:
any:
- resources:
kinds: ["Pod"]
validate:
message: "Privileged containers are not allowed"
pattern:
spec:
containers:
- securityContext:
privileged: "!true"
---
# Require labels:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-labels
spec:
validationFailureAction: Enforce
rules:
- name: check-labels
match:
any:
- resources:
kinds: ["Deployment", "StatefulSet"]
validate:
message: "Labels app and team are required"
pattern:
metadata:
labels:
app: "?*"
team: "?*"
---
# Disallow latest tag:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: disallow-latest-tag
spec:
validationFailureAction: Enforce
rules:
- name: validate-image-tag
match:
any:
- resources:
kinds: ["Pod"]
validate:
message: "Image tag 'latest' is not allowed"
pattern:
spec:
containers:
- image: "!*:latest"
PHẦN 3: MUTATION POLICIES
# Auto-inject default securityContext:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: add-default-security-context
spec:
rules:
- name: add-security-context
match:
any:
- resources:
kinds: ["Pod"]
exclude:
any:
- resources:
namespaces: ["kube-system"]
mutate:
patchStrategicMerge:
spec:
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- (name): "*"
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
---
# Auto-add imagePullSecrets:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: add-image-pull-secret
spec:
rules:
- name: add-pull-secret
match:
any:
- resources:
kinds: ["Pod"]
mutate:
patchStrategicMerge:
spec:
imagePullSecrets:
- name: harbor-registry-creds
PHẦN 4: GENERATION POLICIES
# Auto-create NetworkPolicy for new namespaces:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: generate-default-networkpolicy
spec:
rules:
- name: deny-all-ingress
match:
any:
- resources:
kinds: ["Namespace"]
exclude:
any:
- resources:
names: ["kube-system", "kyverno", "monitoring"]
generate:
synchronize: true
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
name: default-deny-all
namespace: "{{request.object.metadata.name}}"
data:
spec:
podSelector: {}
policyTypes:
- Ingress
- Egress
ingress: []
egress:
- to: []
ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
---
# Auto-create ResourceQuota per namespace:
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: generate-resource-quota
spec:
rules:
- name: create-quota
match:
any:
- resources:
kinds: ["Namespace"]
selector:
matchLabels:
type: application
generate:
synchronize: true
apiVersion: v1
kind: ResourceQuota
name: default-quota
namespace: "{{request.object.metadata.name}}"
data:
spec:
hard:
requests.cpu: "4"
requests.memory: 8Gi
limits.cpu: "8"
limits.memory: 16Gi
pods: "50"
PHẦN 5: IMAGE VERIFICATION
# Require signed images (cosign):
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: verify-image-signature
spec:
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: verify-cosign
match:
any:
- resources:
kinds: ["Pod"]
verifyImages:
- imageReferences:
- "harbor.local/*"
attestors:
- entries:
- keys:
publicKeys: |-
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...
-----END PUBLIC KEY-----
# Sign images with cosign:
cosign generate-key-pair
# Sign:
cosign sign --key cosign.key harbor.local/order-service:v1.0
# Verify:
cosign verify --key cosign.pub harbor.local/order-service:v1.0
PHẦN 6: POLICY REPORTS
# View policy reports:
kubectl get policyreport -A
kubectl get clusterpolicyreport
# Detailed report:
kubectl get policyreport -n default polr-ns-default -o yaml
# Policy violations dashboard:
# Kyverno exports metrics → Prometheus → Grafana
# kyverno_policy_results_total{rule_result="fail"}
💡 KEY TAKEAWAYS
- Kyverno: Kubernetes-native policy engine (YAML, no Rego)
- Validate: Block non-compliant resources
- Mutate: Auto-inject security defaults
- Generate: Auto-create NetworkPolicy, ResourceQuota
- Image verification: Require cosign signatures
- Policy reports: Audit compliance across cluster
🎯 BÀI TẬP
Bài tập 1: Core Policies
- Deploy Kyverno, create validation policies
- Test: deploy pod without limits → should be blocked
- Create mutation policy for securityContext
Bài tập 2: Policy Reports
- Scan existing cluster with Audit mode policies
- Review policy reports for violations
- Switch to Enforce mode after fixing violations
📚 BÀI TIẾP THEO
Trong Bài 38: Falco Runtime Security, chúng ta sẽ implement runtime threat detection.