DirectorySecurity AdvisoriesPricing
Sign in
Directory
kyverno-policies logoHELM

kyverno-policies

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# -- Policy kind (`ClusterPolicy`, `Policy`)
2
# Set to `Policy` if you need namespaced policies and not cluster policies.
3
# Only used when `policyType` is `ClusterPolicy` (the legacy kyverno.io types);
4
# with the default `policyType: ValidatingPolicy` cluster-wide CEL policies are installed.
5
policyKind: ClusterPolicy
6
7
# -- Policy engine type (`ClusterPolicy`, `ValidatingPolicy`)
8
# `ValidatingPolicy` installs CEL-based policies (policies.kyverno.io, requires Kyverno 1.17+).
9
# Set to `ClusterPolicy` to keep installing the legacy kyverno.io policy types,
10
# which are deprecated and will be removed in a future release
11
# (see https://kyverno.io/docs/guides/migration-to-cel/).
12
policyType: ValidatingPolicy
13
14
# -- Pod Security Standard profile (`baseline`, `restricted`, `privileged`, `custom`).
15
# For more info https://kyverno.io/policies/pod-security.
16
podSecurityStandard: baseline
17
18
# -- Pod Security Standard severity (`low`, `medium`, `high`).
19
podSecuritySeverity: medium
20
21
# -- Define podSecuritySeverity overrides for specific policies.
22
# Override the global `podSecuritySeverity` with an individual severity for individual policies.
23
# An empty string per-policy entry suppresses the annotation entirely.
24
podSecuritySeverityByPolicy: {}
25
# disallow-host-path: high
26
# disallow-privileged-containers: high
27
28
# -- Policies to include when `podSecurityStandard` is `custom`.
29
podSecurityPolicies: []
30
31
# -- Additional policies to include from `other`.
32
includeOtherPolicies: []
33
# - require-non-root-groups
34
35
# -- Additional policies to include from `restricted`.
36
includeRestrictedPolicies: []
37
# - require-run-as-non-root-user
38
39
# -- Additional custom policies to include.
40
customPolicies: []
41
# - apiVersion: kyverno.io/v1
42
# kind: ClusterPolicy
43
# metadata: # metadata
44
# spec: # spec
45
46
# -- API server behavior if the webhook fails to respond ('Ignore', 'Fail')
47
# For more info: https://kyverno.io/docs/policy-types/cluster-policy/policy-settings/
48
failurePolicy: Fail
49
50
# -- Validation failure action (`Audit`, `Enforce`).
51
# For more info https://kyverno.io/docs/policy-types/cluster-policy/validate.
52
validationFailureAction: Audit
53
54
# -- Define validationFailureActionByPolicy for specific policies.
55
# Override the defined `validationFailureAction` with a individual validationFailureAction for individual Policies.
56
validationFailureActionByPolicy: {}
57
# disallow-capabilities-strict: Enforce
58
# disallow-host-path: Enforce
59
# disallow-host-ports: Enforce
60
61
# -- Define validationFailureActionOverrides for specific policies.
62
# The overrides for `all` will apply to all policies.
63
validationFailureActionOverrides:
64
all: []
65
# all:
66
# - action: Audit
67
# namespaces:
68
# - ingress-nginx
69
# disallow-host-path:
70
# - action: Audit
71
# namespaces:
72
# - fluent
73
74
# -- Default audit annotations applied to all ValidatingPolicy policies (policyType: ValidatingPolicy only).
75
# Map of annotation key to CEL valueExpression. Audit annotations are recorded in the API server audit log.
76
# For more info https://kyverno.io/docs/policy-types/validating-policy/#using-auditannotations-to-add-custom-data
77
auditAnnotations: {}
78
# policy-evaluated-by: "'kyverno-policies-helm'"
79
80
# -- Define audit annotations for specific ValidatingPolicy policies (policyType: ValidatingPolicy only).
81
# Per-policy entries override defaults when they share the same key.
82
auditAnnotationsByPolicy: {}
83
# disallow-host-path:
84
# violation-details: >-
85
# has(object.spec.volumes) ? 'hostPath volumes found: ' + object.spec.volumes.filter(v, has(v.hostPath)).map(v, v.name).join(', ') : 'no volumes'
86
87
# -- Validate already existing resources.
88
# For more info https://kyverno.io/docs/policy-types/.
89
validationAllowExistingViolations: true
90
91
# -- Exclude resources from individual policies (policyType: ClusterPolicy only).
92
# Policies with multiple rules can have individual rules excluded by using the name of the rule as the key in the `policyExclude` map.
93
# NOTE: This setting only applies when policyType is set to ClusterPolicy. For ValidatingPolicy, use vpolExclude/vpolExcludeByPolicy instead.
94
policyExclude: {}
95
# # Exclude resources from individual policies
96
# disallow-host-path:
97
# all:
98
# - resources:
99
# kinds:
100
# - Pod
101
# namespaces:
102
# - fluent
103
# # Policies with multiple rules can have individual rules excluded
104
# adding-capabilities-strict:
105
# any:
106
# - resources:
107
# kinds:
108
# - Pod
109
# namespaces:
110
# - kube-system
111
112
# -- Default excludes applied to ALL ValidatingPolicy policies (policyType: ValidatingPolicy only).
113
# NOTE: This setting only applies when policyType is set to ValidatingPolicy. For ClusterPolicy, use policyExclude instead.
114
# Supports the following optional keys:
115
# excludeResourceRules: list of Kubernetes NamedRuleWithOperations (native VAP excludes)
116
# excludeNamespaces: list of namespace names to exclude (generates CEL matchCondition)
117
# excludeSubjects: list of subjects to exclude (generates CEL matchCondition)
118
# matchConditions: list of CEL matchConditions for advanced filtering (passthrough of custom condition)
119
# Per-policy overrides via vpolExcludeByPolicy replace these defaults entirely for that policy.
120
vpolExclude: {}
121
# excludeNamespaces:
122
# - kube-system
123
# excludeSubjects:
124
# - kind: Group
125
# name: system:masters
126
127
# -- Per-policy excludes for individual ValidatingPolicy policies (policyType: ValidatingPolicy only).
128
# When set for a policy, it completely replaces the global vpolExclude defaults for that policy.
129
# NOTE: This setting only applies when policyType is set to ValidatingPolicy. For ClusterPolicy, use policyExclude instead.
130
# Each policy name maps to an object with the same keys as vpolExclude.
131
vpolExcludeByPolicy: {}
132
# disallow-host-path:
133
# excludeResourceRules:
134
# - apiGroups:
135
# - ""
136
# apiVersions:
137
# - v1
138
# operations:
139
# - CREATE
140
# - UPDATE
141
# resources:
142
# - pods
143
# # optional - exact resource names to exclude
144
# resourceNames:
145
# - specific-pod-name
146
# excludeNamespaces:
147
# - kube-system
148
# - monitoring
149
# excludeSubjects:
150
# - kind: Group
151
# name: system:masters
152
# - kind: User
153
# name: admin@example.com
154
# - kind: ServiceAccount
155
# namespace: kube-system
156
# name: default
157
# matchConditions:
158
# - name: exclude-custom
159
# expression: "!object.metadata.name.startsWith('temp-')"
160
161
# -- Add preconditions to individual policies.
162
# Policies with multiple rules can have individual rules excluded by using the name of the rule as the key in the `policyPreconditions` map.
163
policyPreconditions: {}
164
# # Exclude resources from individual policies
165
# require-run-as-non-root-user:
166
# all:
167
# - key: "{{ request.object.metadata.name }}"
168
# operator: NotEquals
169
# value: "dcgm-exporter*"
170
# # Policies with multiple rules can have individual rules excluded
171
# require-drop-all:
172
# any:
173
# - key: "{{ request.object.metadata.name }}"
174
# operator: NotEquals
175
# value: "dcgm-exporter*"
176
# adding-capabilities-strict:
177
# all:
178
# - key: "{{ request.object.metadata.name }}"
179
# operator: NotEquals
180
# value: "dcgm-exporter*"
181
182
# -- Customize the target Pod controllers for the auto-generated rules. (Eg. `none`, `Deployment`, `DaemonSet,Deployment,StatefulSet`)
183
# For more info https://kyverno.io/docs/policy-types/cluster-policy/autogen/.
184
autogenControllers: ""
185
186
# -- Name override.
187
nameOverride:
188
189
# -- Additional Annotations.
190
customAnnotations: {}
191
192
# -- Define custom annotations for specific policies.
193
# Per-policy entries override defaults when they share the same key.
194
customAnnotationsByPolicy: {}
195
# disallow-host-path:
196
# my-custom-annotation: "some-value"
197
198
# -- Additional labels.
199
customLabels: {}
200
201
# -- Policies background mode
202
background: true
203
204
# -- (bool) SkipBackgroundRequests bypasses admission requests that are sent by the background controller
205
skipBackgroundRequests: ~
206
207
# -- Kyverno version
208
# The default of "autodetect" will try to determine the currently installed version from the deployment
209
kyvernoVersion: autodetect
210
211
# -- Kubernetes version override
212
# Override default value of kubeVersion set by release team taken from Chart.yaml with custom value. Ideally range of versions no more than two prior (ex., 1.28-1.31), must be enclosed in quotes.
213
kubeVersionOverride:
214

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.