Introducing CEL Policies

Unified Policy As Code For Platform Engineers

Kyverno, created by Nirmata, makes it simple to secure, automate, and manage your infrastructures and applications using Kubernetes-native YAML and CEL. Easy-to-learn and powered by the CNCF community.

Kubernates Native
Flexible
Enhanced Performance
Created by Nirmata

why Kyverno

Kyverno, created by Nirmata is the Kubernetes-native policy engine designed to simplify security, compliance, and automation by letting you manage policies the same way you manage your cluster.

Kubernates Native

  • Uses YAML & CEL, languages familiar to K8s users
  • Write & apply policies as CRDs

Easy to Adopt

  • Quick and easy to get started with
  • Designed for K8s

Flexible & Powerful

  • Wide range of use cases
  • Fits naturally into existing workflows

Trusted & Proven

  • CNCF incubating project
  • Widely adopted & used in Production by orgs of all sizes

Kyverno Vs Other policy engines

As the industry's leading policy engine, here's how Kyverno compares with other policy engines.

Policy Language
kyverno logoSupports YAML & CEL-based policies (languages familiar to K8s users)
opa logoRego (new DSL to learn)
Ease of Adoption
kyverno logoIntuitive, no extra learning curve
opa logoSteeper learning curve due to Rego
Policy Types
kyverno logoValidate, Mutate, Generate, Verify, Delete
opa logoValidate

Complete Platform Engineering Policy As Code Solution

From policy creation to enforcement, testing to reporting, and everything in between, get comprehensive Kubernetes governance and compliance with Kyverno.

Kubernetes Native

Extends and completes Kubernetes policy types for comprehensive platform engineering capabilities.

Works Everywhere

Executes Kubernetes-style policies on any JSON payload using CLI or SDK for universal compatibility.

Integrated Reporting

OpenReports compatible producers, routers, and dashboards for comprehensive policy compliance visibility.

Exception Management

Timebound and fine-grained exception management decoupled from policies for flexible governance.

Shift-Left Integration

CLI for seamless integrations into CI/CD and Infrastructure as Code (Terraform, etc.) pipelines.

Policy Testing

Comprehensive tooling for declarative unit tests and end-to-end behavioral policy validation.

CEL Performance

Enhanced performance with Common Expression Language for faster policy, evaluation and execution.

Version Control

Full version control integration with GitOps workflows for policy lifecycle management.

Security Policies

Comprehensive security policy templates and best practices for zero-trust architectures.

Get started with Kyverno

Deploy Kyverno in your Kubernetes cluster within minutes and start writing policies using simple, familiar YAML.

Trusted By Industry Leaders

Powering policy management for organizations worldwide

product iconsproduct iconsproduct iconsproduct iconsproduct iconsproduct iconsproduct iconsproduct iconsproduct iconsproduct iconsproduct icons

Join 1000+ organizations using Kyverno in production environments

Join us

Kyverno is a CNCF Incubating Project

cncf logo

The Linux Foundation® (TLF) has registered trademarks and uses trademarks. For a list of TLF trademarks, see Trademark Usage.