---
tags:
- k8s
- l1
- flashcard-deck
- policy-engines
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Policy Engines](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
policy-engines/a1b2c3d4e5f0	policy-engines	easy	policy-engines, opa, kyverno	What is the fundamental difference between Kubernetes RBAC and a policy engine like OPA Gatekeeper or Kyverno?	"RBAC controls who can perform an action (identity-based, e.g., ""can this user create a Deployment?""). Policy engines control what content is allowed (content-based, e.g., ""does this Deployment have resource limits?"").\n\nExample: OPA evaluates ""Can user X deploy to production?"" by checking a Rego policy against input JSON. Decouples policy from application code.\n\nRemember: ""OPA = universal policy brain, Rego = its language.""\n\nName origin: OPA = Open Policy Agent. Created by Styra, donated to CNCF. Graduated project since 2021."	training/library/topics/policy-engines/primer.md
policy-engines/b2c3d4e5f0a1	policy-engines	easy	policy-engines, kyverno, policy-types	What are the four policy types that Kyverno supports?	"Validate (block or warn on non-compliant resources), Mutate (automatically modify resources), Generate (auto-create companion resources), and VerifyImages (check container image signatures).\n\nExample: deny[msg] { input.request.kind.kind == ""Pod""; not input.request.object.spec.securityContext.runAsNonRoot; msg := ""Pods must run as non-root"" }\n\nRemember: ""Rego = query language, not imperative. Think SQL for policies.""\n\nRemember: ""VMGV = Validate, Mutate, Generate, VerifyImages."" Kyverno\'s four superpowers."	training/library/topics/policy-engines/primer.md
policy-engines/c3d4e5f0a1b2	policy-engines	easy	policy-engines, admission-control	What is the difference between Enforce and Audit mode for policy engines?	"Enforce mode rejects non-compliant resources at admission time, preventing them from being created. Audit mode allows the resources but logs violations for review, letting you assess impact before enforcing.\n\nExample: package kubernetes.admission -- violation[{""msg"": msg}] { ... } — Gatekeeper watches admission requests and rejects those matching violation rules.\n\nRemember: ""OPA = library, Gatekeeper = K8s-native OPA with CRDs.""\n\nRemember: ""Audit first, enforce second."" Rolling out enforcement without auditing first will block legitimate workloads."	training/library/topics/policy-engines/primer.md
policy-engines/d4e5f0a1b2c3	policy-engines	medium	policy-engines, opa, gatekeeper	In OPA Gatekeeper, what are the two resources needed to define and apply a policy?	"A ConstraintTemplate (defines the policy logic in Rego) and a Constraint (applies the template with specific parameters and match criteria). The template defines what to check; the constraint defines where to check it and with what parameters.\n\nGotcha: Test policies with opa test before deploying. A bad policy can block all deployments.\n\nExample: opa eval -i input.json -d policy.rego ""data.example.allow"""	training/library/topics/policy-engines/primer.md
policy-engines/e5f0a1b2c3d4	policy-engines	medium	policy-engines, opa, kyverno, comparison	What are two key differences between OPA Gatekeeper and Kyverno in terms of policy language and mutation support?	"OPA Gatekeeper uses Rego (a custom DSL with a steep learning curve) and has limited mutation support. Kyverno uses native YAML (low learning curve) and has first-class mutation and resource generation capabilities.\n\nRemember: ""Conftest = OPA for config files."" It catches misconfigurations before they reach the cluster.\n\nExample: conftest test --policy ./policy deployment.yaml\n\nInterview tip: Choose Kyverno for K8s-only, YAML-native policies. Choose OPA for cross-system policies (K8s + CI + APIs)."	training/library/topics/policy-engines/primer.md
policy-engines/f0a1b2c3d4e5	policy-engines	medium	policy-engines, kyverno, mutation	How does a Kyverno mutate policy work? Give an example use case.	"A mutate policy automatically modifies resources as they are admitted. For example, a patchStrategicMerge rule can add default labels (managed-by: kyverno, environment: {{request.namespace}}) to every Pod created, without requiring developers to add them manually.\n\nExample: A ConstraintTemplate defines the Rego logic; a Constraint applies it to specific resources. Think of templates as policy classes and constraints as instances.\n\nRemember: ""Template = schema + logic, Constraint = where to apply it.""\n\nExample: Auto-add `managed-by: kyverno` label to every Pod. Developers never need to remember — the policy handles it."	training/library/topics/policy-engines/primer.md
policy-engines/01a2b3c4d5e6	policy-engines	medium	policy-engines, pod-security-standards	What are the three Pod Security Standards levels in Kubernetes, and what does each allow?	"Privileged: everything (no restrictions). Baseline: prevents known privilege escalations. Restricted: strongly restricted (non-root, no capabilities, read-only root filesystem). They are applied via namespace labels like pod-security.kubernetes.io/enforce=restricted.\n\nRemember: ""Shift-left = catch earlier, fail faster."" Policy in CI means broken configs never reach staging.\n\nExample: conftest test in a GitHub Actions step blocks PRs with policy violations.\n\nTimeline: Pod Security Standards replaced the deprecated PodSecurityPolicy in Kubernetes 1.25 (2022)."	training/library/topics/policy-engines/primer.md
policy-engines/12b3c4d5e6f7	policy-engines	hard	policy-engines, opa, rego	In Rego, how would you write a policy to deny containers using the :latest image tag or no tag at all?	"Two violation rules: one checks endswith(container.image, "":latest"") and another checks not contains(container.image, "":"") (which defaults to latest). Both iterate over input.review.object.spec.containers[_] and return a violation message with the container name.\n\nGotcha: OPA bundles update periodically — there is a propagation delay. For real-time policy changes, reduce the bundle polling interval.\n\nExample: OPA can pull bundles from S3, GCS, or an HTTP server."	training/library/topics/policy-engines/primer.md
policy-engines/23c4d5e6f7a8	policy-engines	hard	policy-engines, kyverno, generation	How does a Kyverno generate policy work, and why is auto-generating a default-deny NetworkPolicy on namespace creation valuable?	"A generate rule triggers when a matched resource is created (e.g., a Namespace) and automatically creates another resource (e.g., a NetworkPolicy with empty podSelector and Ingress+Egress policyTypes). This ensures every new namespace starts with network segmentation by default, closing the gap between namespace creation and security hardening.\n\nExample: Sentinel policy: main = rule { all tfplan.resources.aws_instance as _, instances { instances.applied.instance_type in [""t3.micro"", ""t3.small""] } }\n\nSentinel vs OPA: Sentinel is HashiCorp-only; OPA is vendor-neutral and open source.\n\nRemember: ""Generate = auto-create companion resources."" Most commonly: auto-create NetworkPolicy on namespace creation."	training/library/topics/policy-engines/primer.md
policy-engines/34d5e6f7a8b9	policy-engines	hard	policy-engines, rollout, pitfalls	What is the recommended rollout strategy for policy engines, and why is setting failurePolicy: Ignore important?	Deploy policies in Audit mode first, review violations, fix existing non-compliant resources, then switch to Enforce. Setting failurePolicy: Ignore on the webhook is important because if the policy engine (Kyverno/Gatekeeper) goes down, the webhook would otherwise block all resource creation cluster-wide.\n\nGotcha: `failurePolicy: Fail` means if Gatekeeper/Kyverno crashes, ALL resource creation is blocked cluster-wide. Use `Ignore` with compensating audit controls.	training/library/topics/policy-engines/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Interview: Kyverno Blocking Deploys](../../../../library/interview-scenarios/18-kyverno-blocking-deploys.md) (Scenario, L2) — Policy Engines
- [Multi-Tenancy Patterns](../../../../library/topics/multi-tenancy/index.md) (Topic Pack, L2) — Policy Engines
- [Policy Engine Drills](../../../../library/drills/policy_engine_drills.md) (Drill, L2) — Policy Engines
- [Policy Engines (OPA / Kyverno)](../../../../library/topics/policy-engines/index.md) (Topic Pack, L2) — Policy Engines
- [Runbook: Kyverno Blocking Workloads](../../../../library/runbooks/kubernetes/kyverno_blocking_workloads.md) (Runbook, L2) — Policy Engines
- [Skillcheck: Policy Engines](../../../../library/skillchecks/policy-engines.skillcheck.md) (Assessment, L2) — Policy Engines

<!-- wiki:related:end -->
