Introduction to Kyverno
Workshop

Platform teams usually know which rules should apply to their Kubernetes clusters: no privileged containers, only approved images, and consistent requirements for labels or networking. The difficult part is checking those rules reliably, documenting exceptions, and introducing changes without unexpectedly blocking deployments. Kyverno represents these requirements as Kubernetes resources. Rules are written in CEL and can validate requests, change or generate resources, remove test resources on a schedule, and verify images. The workshop connects policy authoring with tests, reports, exceptions

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerBITMARCKUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosInheadenSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Workshop overview

Duration, per-participant price and logistics for Introduction to Kyverno.

On-site options

  • Live online or on-site at your location

  • In-house: content, duration and focus can be tailored

  • Flexible dates, from 1 participant

  • German; English on request

  • Preconfigured cloud lab (also on-site)

  • Open groups: max. 8 people

  • Seat price same as online: €721.50 × days, excl. VAT

  • On-site in-house: individual quote (travel/logistics as incurred)

  • No published flat on-site surcharge

  • You provide the training room and internet

  • Open sessions: 09:00–16:00 (CET/CEST)

Curriculum

Topics by day at a glance.

Day 1: Write, test, and introduce Kubernetes policies step by step

  • Compare Kubernetes Validation with Kyverno
  • CEL Fundamentals for Kubernetes Rules
  • Develop and Test a Validation Rule
  • Interpret Policy Results Correctly
  • Move from Observation to Blocking
Day 1

Day 2: Update, generate, and selectively delete Kubernetes resources

  • Add Workload Defaults Without Conflicts
  • Coordinate Changes with GitOps
  • Generate Namespace Standards Automatically
  • Limit Deletion Rules to Test Resources
  • Evaluate External Data Sources for Policies
Day 2

Day 3: Verify images, test policies in CI, and diagnose one failure

  • Define Trust Rules for Container Images
  • Verify Signatures and Attestations
  • Integrate Policy Tests into CI
  • Diagnose One Webhook Outage with Guidance
  • Migrate Existing Kyverno Policies Deliberately
Day 3

Workshop schedule

Published daily rhythm. Topics are listed in the curriculum.

09:00–16:00 (CET/CEST)

Official window for open sessions.

Frame

09:00 – Introductions

On day 1: meet the instructor and participants, plus the agenda and workshop structure.

Day 1

09:00 – Q&A

On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).

Later days

Content blocks follow the curriculum

Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.

Topics

12:00–13:00 – Lunch

A shared break before the afternoon.

Break

16:00–16:30 – Q&A

End of the day: questions, exchange and wrap-up.

Close

Prerequisites

What participants should bring.

Hardware

Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.

HardwareNotebook

Environment

Each participant works in a provided cloud lab. Local installation of the training stack is not required.

LabCloud

Prerequisites

Basic Linux/terminal skills are helpful.

Prerequisites

Related workshops

Suggested follow-on courses from the catalog.