Kyverno — admission control policies for image signing and PSS
Kubernetes admission controllers intercept API requests before they are persisted to etcd, allowing a validating webhook to reject requests that violate policy or a mutating webhook to modify requests to enforce defaults. Without admission control, any workload that can authenticate to the Kubernetes API can deploy containers with privileged access, mount host filesystems, use unsigned images, or run as root—regardless of the GitOps repository's declared configuration.
Kyverno is a Kubernetes-native policy engine that implements both validating and mutating admission webhooks through declarative YAML policies, requiring no Rego or custom code. Kyverno ClusterPolicies can require Cosign image signatures as a deployment gate, enforce Pod Security Standards, generate default security contexts on new pods, and audit existing resources for policy compliance. As a Kubernetes CRD, Kyverno policies are themselves managed by GitOps and subject to the same review process as application manifests.
Analogy🏏Cricket
Think of it like cricket: Imagine the BCCI's team management system for an international tour with matches in three different countries simultaneously. Rather than a coordinator manually managing each match day's logistics, the system reads the official tour schedule document and automatically dispatches the right squad, equipment, and support staff to each venue. When the tour schedule changes—a match is rescheduled, a squad member is replaced—the system detects the change and updates the arrangements automatically. Just as the tour management system uses the official document as the source of truth and orchestrates multiple concurrent deployments to multiple venues, ArgoCD uses the Git repository as the source of truth and orchestrates multiple concurrent Application syncs to multiple clusters. Just as the system provides a dashboard showing which venues are 'ready', 'delayed', or 'degraded', ArgoCD provides a dashboard showing which Applications are Synced, OutOfSync, or Degraded. This reveals why ArgoCD is valued at scale: managing dozens of applications across multiple clusters manually is operationally equivalent to coordinating an international cricket tour by phone.
🏏 Showing the Cricket analogy — a Cricket version isn’t available for this concept yet.