Co-founder and CEO at @NirmataCloud | Kubernetes Policy Management

Joined November 2010
40 Photos and videos
Jim Bugwadia retweeted
Here is the link to my Kyvernocon talk about "Policy as a Code for LLM Inference: Cost and Security Guardrails" youtu.be/XIQ7ujr8c74?si=B3hc… @kyverno @CloudNativeFdn @kubernetesio
3
3
279
Jim Bugwadia retweeted
AI agents are accelerating code delivery but exploding the attack surface. Is your production cluster open to unsigned images? 🛡️ Learn how to build a protected promotion pipeline with Harbor, Cosign, and Kyverno. #DevSecOps #CloudSecurity hackersvanguard.com/secure-c…
1
2
26
Jim Bugwadia retweeted
I just attended #KyvernoCon Virtual 2026. Great insights on policy-driven Kubernetes, security, and governance. Big thanks to @TechTalkingMom for organizing such a valuable event 🙌 Open source keeps getting stronger 💙 @kyverno #Kubernetes #OpenSource #CloudNative #CNCF
1
6
10
233
Jim Bugwadia retweeted
Kyverno (Issue #016) can enforce this at admission. Reject CNPG Cluster resources that don't have a properly-sized PDB zone anti-affinity. One policy, half the quorum-PDB mistakes prevented at deploy time. Governance earning its keep on stateful workloads. podostack.com/p/postgres-on-… 🛡️
2
3
149
Jim Bugwadia retweeted
Workflow that earns its keep: 1. Scheduled Job runs kor all --output json per namespace 2. Findings to Slack, per-team 3. High-confidence categories (abandoned Secrets > 90 days, empty Services > 30) promoted to Kyverno CleanupPolicy Inventory → governance → automation.
2
1
1
21
Jim Bugwadia retweeted
Apr 30
Part 3: ️Kyverno vs OPA Gatekeeper — Kubernetes Policy-as-Code Showdown medium.com/@kdeepak99/part-3…

2
9
302
Jim Bugwadia retweeted
Kube GitOps Lab 02 is live: Kyverno admission control via ArgoCD on a single-node k3s cluster. Covers sync waves, ignoreDifferences gotchas, 4 baseline ClusterPolicies, and the Audit -> Enforce lifecycle. medium.com/p/kube-gitops-lab… #Kubernetes #GitOps #DevOps #Kyverno
2
1
52
Jim Bugwadia retweeted
Full #Observability for #Kyverno With #ObservabilityasCode The adoption of Kyverno solves the challenge of #PolicyasCode. However, a new question emerges for platform engineers: what happens when a slow policy rule adds latency? A slow admission webhook can degrade performance across the #Kubernetes cluster. youtu.be/V5EQLMVI894?si=cfwA…
1
3
132
Jim Bugwadia retweeted
🚨 The #KyvernoCon Virtual schedule is LIVE! Join us May 8 for real-world talks on: ✔️ Policy as Code ✔️ Platform Engineering ✔️ Security AI governance 🎤 Speakers from across the Kyverno ecosystem 🌍 Built for our global community 👉 Register now: community.cncf.io/events/det…
2
4
4
299
AI agents come in several different forms. Here is a simple classification we have been using internally. This can be useful for both builders and end users, who need to govern agents. How do you categorize agents? nirmata.com/2026/03/26/a-fie…
2
26
Jim Bugwadia retweeted
Giving devs self-service infra without guardrails is like giving them root. Here's how to prevent $10K RDS instances with one Kyverno policy. podostack.com/p/crossplane-i…
1
1
2
32
Jim Bugwadia retweeted
Generate: when a dev creates a DatabaseClaim, Kyverno can auto-create a matching BackupPolicy resource. No manual step. No Jira ticket. The policy ensures every database gets backups. Zero human intervention.
1
1
1
30
Jim Bugwadia retweeted
Self-service doesn't mean no rules. It means the rules are automated. Kyverno validates. Crossplane provisions. Secrets flow to pods. Devs get databases in minutes. Platform team sleeps. Full guide with policy examples: podostack.com/p/crossplane-i… 🛠️
1
1
20