Skip to content
This repository was archived by the owner on Dec 18, 2025. It is now read-only.

Update Kyverno self-assessment#1486

Merged
eddie-knight merged 9 commits intocncf:mainfrom
realshuting:main
Aug 15, 2025
Merged

Update Kyverno self-assessment#1486
eddie-knight merged 9 commits intocncf:mainfrom
realshuting:main

Conversation

@realshuting
Copy link
Contributor

This PR updates the Kyverno self-assessment document with the most current and accurate security information, as of Kyverno v1.15.0 release, to reflect our current security posture and practices.

Signed-off-by: ShutingZhao <shuting@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
@netlify
Copy link

netlify bot commented Aug 1, 2025

Deploy Preview for tag-security ready!

Name Link
🔨 Latest commit 3371eca
🔍 Latest deploy log https://app.netlify.com/projects/tag-security/deploys/689f0198d2938b0008dda173
😎 Deploy Preview https://deploy-preview-1486--tag-security.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Copy link
Collaborator

@JustinCappos JustinCappos left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the goals and non-goals could use a little bit of lovin' here, but overall it's in a decent shape for a self assessment.

I do think that the failure modes / activities would need to be clarified in a lot more detail to be ready for a joint assessment. However, this could be merged with just the goals / non-goals changes, if desired.

![Kyverno Logical Architecture](images/kyverno-architecture.png)

### Webhook
Kyverno consists of four main controllers that work together to provide comprehensive policy management capabilities. Each controller handles specific aspects of policy processing, from admission control to background operations and cleanup tasks.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One of the big things you'd need to do for a joint assessment is to describe how a flaw / breach related to each of the controllers would impact users as a whole.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for highlighting that important requirement. We will address the impact analysis for each controller during the joint assessment phase, where we can thoroughly evaluate how potential flaws or breaches would affect users across the system. This will be a key component of our comprehensive security review.

Signed-off-by: ShutingZhao <shuting@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Copy link
Collaborator

@JustinCappos JustinCappos left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks. This is in a mergable state now. As noted, there will be a moderate amount of work to get to the state where we could do a joint assessment.

@JustinCappos
Copy link
Collaborator

FYI: I'm not sure why the link checker is failing. @eddie-knight

Otherwise, this is ready to merge.

@eddie-knight eddie-knight merged commit 0f6f948 into cncf:main Aug 15, 2025
8 of 10 checks passed
@realshuting
Copy link
Contributor Author

Okay, thanks. This is in a mergable state now. As noted, there will be a moderate amount of work to get to the state where we could do a joint assessment.

Thank you Justin for your review and guidance. We're ready to tackle the work required to prepare for the joint assessment, and are looking forward to working with you on this next phase.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants