Kyverno

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

Kyverno is ranked #23 of 24 in infrastructure policy as code tools on Inferse. It runs on API, Linux, macOS, Self-hosted, Windows. There is a free plan.

Compared on infrastructure policy as code tools

Kubernetes security
Yeskyverno.io
Admission control
Yeskyverno.io
Deployment model
self_hostedkyverno.io

Facts

Purpose
Kyverno is a Kubernetes-native policy engine for defining and enforcing policy as code.github.com · 4 Oct 2026
Policy language
Kyverno supports CEL-based policy types and describes applying Kubernetes-style policies outside Kubernetes as part of its mission.kyverno.io · 4 Oct 2026
Policy actions
Its stable policy types can validate, mutate, generate, and delete resources, and verify container image signatures and attestations.kyverno.io · 4 Oct 2026
CI testing
The Kyverno CLI can test policies in CI pipelines against Kubernetes resource manifests before they are applied to a live cluster.kyverno.io · 4 Oct 2026
Integrations
The documentation describes using Kyverno with Helm, YAML manifests, GitHub Actions, and GitOps tools such as ArgoCD.kyverno.io · 4 Oct 2026
Deployment
Kyverno is installed in a Kubernetes cluster, with Helm recommended for production deployments and YAML manifests also available.kyverno.io · 4 Oct 2026
Availability
A standard installation has a required admission controller and optional background, reports, and cleanup controllers; production installations should use high availability mode.kyverno.io · 4 Oct 2026
Security
Kyverno’s documentation describes Cosign signatures for container images and manifests and lists release artifacts including CLI binaries for Linux, macOS, and Windows.kyverno.io · 4 Oct 2026
Security review
The project documents a 2023 third-party security audit and security assessments conducted as part of its CNCF graduation process.kyverno.io · 4 Oct 2026
Operational consideration
Kyverno’s resource webhooks default to fail-closed, so matching resource requests can fail when the API server cannot reach Kyverno.kyverno.io · 4 Oct 2026
Legacy policy limit
The documentation marks legacy ClusterPolicy and CleanupPolicy types deprecated in v1.19 and says they are scheduled for removal in v1.20.kyverno.io · 4 Oct 2026
Support
The project directs users to its Kubernetes Slack channels, GitHub, and mailing list for questions and discussion.kyverno.io · 4 Oct 2026
Intended users
The project describes Kyverno as designed for platform engineering teams and enabling security, compliance, automation, and governance through policy as code.github.com · 4 Oct 2026
Project status
The CNCF lists Kyverno as a Graduated project, with graduation recorded in March 2026.cncf.io · 4 Oct 2026

Company

Founded
2019kyverno.io · 28 Sept 2026

Best Kyverno alternatives

See all 12