2.1 KiB
Kyverno policy baseline
These policies are ClusterPolicy resources. The workload hardening policies
select only namespaces labeled security-baseline/open: "true". The separate
disallow-default-namespace policy specifically protects the Kubernetes
default namespace. This keeps the portfolio demo enforceable without
blocking Kyverno, Falco, ArgoCD, or other platform components.
All six policies use validationFailureAction: Enforce, so a matching resource is
rejected at admission time. The policies use background: false because the
goal is to demonstrate admission enforcement, not retroactively evaluate
existing objects.
| Policy | CIS alignment | Enforcement |
|---|---|---|
disallow-privileged |
5.2.2 | Rejects privileged containers and init containers. |
require-non-root |
5.2.7 | Requires runAsNonRoot: true on containers and init containers. |
require-resource-limits |
5.7.3 supplemental | Requires CPU and memory limits. This is a supplemental control, not a one-to-one CIS test. |
restrict-image-registries |
5.5.1 supplemental | Allows only approved registries. Full image provenance requires signing and verification as well. |
disallow-default-namespace |
Supplemental | Blocks common application resources from being created in default, which makes namespace ownership explicit. |
disallow-host-network |
5.2.3 and 5.2.5 | Rejects host PID, host network, and host IPC access. |
The default-namespace policy intentionally excludes ConfigMaps and Secrets. Those objects are supporting data, not application entrypoints, and blocking them alone would not prevent a workload from being installed. Keeping them out also avoids adding broad read permissions for Secret data to Kyverno's reports controller. Applications should create these objects in the same explicitly named namespace as the workloads that consume them.
The CIS benchmark includes manual checks and platform-specific exceptions. The mapping above describes the control objective each policy supports, not a claim that one Kyverno rule implements the entire benchmark control.