Kyverno
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
IaC Security
Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.
17 tools profiled
How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.