AI agents are accelerating code delivery but exploding the attack surface. Is your production cluster open to unsigned images? 🛡️ Learn how to build a protected promotion pipeline with Harbor, Cosign, and Kyverno. #DevSecOps#CloudSecurityhackersvanguard.com/secure-c…
Kyverno (Issue #016) can enforce this at admission.
Reject CNPG Cluster resources that don't have a properly-sized PDB zone anti-affinity. One policy, half the quorum-PDB mistakes prevented at deploy time.
Governance earning its keep on stateful workloads.
podostack.com/p/postgres-on-… 🛡️
Jim Bugwadia on why finding a Kubernetes problem is only half the battle for Kyverno users devopschat.co/articles/jim-b… - Explore Kyverno's journey to CNCF graduation, a pivotal to...
Kube GitOps Lab 02 is live: Kyverno admission control via ArgoCD on a single-node k3s cluster.
Covers sync waves, ignoreDifferences gotchas, 4 baseline ClusterPolicies, and the Audit -> Enforce lifecycle.
medium.com/p/kube-gitops-lab…#Kubernetes#GitOps#DevOps#Kyverno
🚨 The #KyvernoCon Virtual schedule is LIVE!
Join us May 8 for real-world talks on: ✔️ Policy as Code
✔️ Platform Engineering
✔️ Security AI governance
🎤 Speakers from across the Kyverno ecosystem
🌍 Built for our global community
👉 Register now:
community.cncf.io/events/det…
AI agents come in several different forms. Here is a simple classification we have been using internally. This can be useful for both builders and end users, who need to govern agents. How do you categorize agents?
nirmata.com/2026/03/26/a-fie…
Giving devs self-service infra without guardrails is like giving them root.
Here's how to prevent $10K RDS instances with one Kyverno policy.
podostack.com/p/crossplane-i…
Generate: when a dev creates a DatabaseClaim, Kyverno can auto-create a matching BackupPolicy resource.
No manual step. No Jira ticket. The policy ensures every database gets backups. Zero human intervention.
Self-service doesn't mean no rules. It means the rules are automated.
Kyverno validates. Crossplane provisions. Secrets flow to pods. Devs get databases in minutes. Platform team sleeps.
Full guide with policy examples:
podostack.com/p/crossplane-i… 🛠️