dhi.io/kyverno-policies-chart
Kubernetes Pod Security Standards implemented as Kyverno policies.
Kyverno Policies is a curated library of Kyverno ClusterPolicy (and CEL-based ValidatingPolicy) resources that
implement the Kubernetes Pod Security Standards at the baseline or
restricted level. Installing this chart adds policy custom resources to your cluster that Kyverno evaluates against
incoming workloads, enforcing or auditing security best practices such as disallowing privileged containers, host
namespaces, and unsafe capabilities.
This chart is image-less: it does not deploy any container images or Pods. It requires the Kyverno admission controller and its Custom Resource Definitions (CRDs) to already be installed and running in the cluster, since Kyverno is the engine that evaluates the policies this chart creates.
Docker Hardened Images are built to meet the highest security and compliance standards. They provide a trusted foundation for containerized workloads by incorporating security best practices from the start.
These images are published with near-zero known CVEs, include signed provenance, and come with a complete Software Bill of Materials (SBOM) and VEX metadata. They're designed to secure your software supply chain while fitting seamlessly into existing Docker workflows.
Kyverno® and Kubernetes® are trademarks of the Linux Foundation. All rights in the marks are reserved to the Linux Foundation. Any use by Docker is for referential purposes only and does not indicate sponsorship, endorsement, or affiliation.
Try DHI Enterprise
Start a free 30-day DHI Enterprise trial to mirror this image to your organization's registry and unlock full benefits.
SLA-backed CVE remediations
FIPS & STIG-compliant variants
Customizations at enterprise scale
Join GitHub Discussions or our Slack community to share ideas, ask questions, and connect with the team.
Go to discussionsJoin community