Validate, mutate, and generate resources using Kubernetes-native YAML and CEL across all infrastructure. Easy-to-learn and powered by the CNCF community.
Validate, mutate, and generate resources using Kubernetes-native YAML and CEL across all infrastructure. Easy-to-learn and powered by the CNCF community.
Kyverno is an open‑source policy engine for your entire cloud infrastructure that uses YAML and CEL generated policies that you know and are familiar with. Use Kyverno to validate configurations, mutate them to match standards, and generate required resources automatically.
Policies are custom resources that work along with Kubernetes
Apply policies to IaC & CI/CD, enforce in clusters, and check cloud resources
Use common YAML to define a policy and embed CEL expressions to provide validation logic
Admission control, background scans, and policy reports
Works with major Kubernetes distros, CI/CD tools, and cloud platforms
Automate guardrails and validate manifests in CI/CD pipelines
Works with Argo CD and Flux. Great fit for pull-request workflows
CNCF project with over 3 billion downloads, and active contributors and examples
Enforce best practices, block risky settings, require labels, and ensure images come from approved registries
Auto‑insert defaults, annotations, limits, and security settings so resources meet your standards
Create supporting resources on-the-fly: ConfigMaps, NetworkPolicies, and more—based on rules you define
Continuously scan workloads and produce policy reports to track compliance over time
Get started with Kyverno and add-on Nirmata when you need enterprise-grade operations and AI‑powered governance.
Start with Kyverno and then add Nirmata Enterprise for Kyverno when you want an enterprise-grade lifecycle, health checks, SLAs, and reporting. Further add Nirmata Control Hub when you want a central control layer, dashboards, and AI agents with a natural‑language AI Copilot.
Kyverno is a Cloud Native Computing Foundation incubating project built and maintained with the community. Nirmata helps lead the project and provides enterprise‑grade operations and AI‑assisted governance when you need it.
Start with open‑source policy‑as‑code in YAML and CEL. When you’re ready to scale and automate, add Nirmata.