Тёмный

Kubernetes-Native Policy Management With Kyverno 

DevOps Toolkit
Подписаться 77 тыс.
Просмотров 13 тыс.
50% 1

Опубликовано:

 

22 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 43   
@DevOpsToolkit
@DevOpsToolkit 3 года назад
What do you think about Kyverno? Is it a good alternative to OPA/Gatekeeper? Should I compare the two in one of the upcoming videos? I made a mistake in the video by saying that it did not work in k3d. When I tried it again a while later, everything worked like a charm. My guess is that there was a temporary problem or an issue I caused when I was recording the session. In any case, I stand corrected. it works in k3d!!! Make sure to check out github.com/fjogeleit/policy-reporter. It helps with a better view of the reports.
@bewilderedlearningevolving
@bewilderedlearningevolving 3 года назад
Kyverno is interesting, I guess not having to learn Rego is good, but may be more powerful in the end? Thanks Viktor, looking forward to the next one.
@ziaurrehman4738
@ziaurrehman4738 2 года назад
Can we restrict to create service of a type load balancer on the base of label or annotation with kyverno?
@DevOpsToolkit
@DevOpsToolkit 2 года назад
Yes we can. We can filter resources to which policies are applied using any resource field.
@dude2093
@dude2093 2 года назад
Really great video. Refreshing to see you start with a concrete example
@leonchik1976
@leonchik1976 3 месяца назад
Great overview, thank you!
@rodoherty1
@rodoherty1 Год назад
Very useful! Thanks, Victor!
@MrChandiprasad
@MrChandiprasad 2 года назад
Very well explained , with simple examples !
@aleksandrarestov7150
@aleksandrarestov7150 3 года назад
Thank you! I think I apply it in my work.
@oussamasafi1565
@oussamasafi1565 3 года назад
Great overview, thank you Viktor
@quant-daddy
@quant-daddy 3 года назад
excellent video as always!!
@edithpuclla6188
@edithpuclla6188 2 года назад
Amazing! I just found this video, and I your fan now! Subsrcribed!
@edmilsonjunior910
@edmilsonjunior910 2 года назад
Great explanation!
@aranyadas5919
@aranyadas5919 3 года назад
Just saw your video on Gatekeeper day before yesterday,and sent a presentation to the higher ups in the office as to why maybe we should start using Gatekeeper and other security tools in our AKS.and now this😂😂
@DevOpsToolkit
@DevOpsToolkit 3 года назад
My thinking is similar. I believe that openshift/okd makes sense for the companies that need that complexity and often want to pay a high price for a solution. OKD is mostly used as a way to evaluate OpenShift rather than a final solution.
@PankajSharma-di7dz
@PankajSharma-di7dz 3 года назад
Very Good overview, Thanks for sharing..:)
@Stvcloud
@Stvcloud 3 года назад
Awesome!
@chandup
@chandup 3 года назад
Great video. Thank you. Please compare gatekeeper and kyverno.
@DevOpsToolkit
@DevOpsToolkit 3 года назад
It's coming... I hope to have it done in 2 weeks from now.
@StieglmaierThomas
@StieglmaierThomas 3 года назад
@@DevOpsToolkit maybe you want to throw kubewarden.io into the mix? I didn't use it up to now, and I think that Kyverno looks already much easier, but maybe you value the complexity because things are possible with it, that I am now not even thinking of
@DevOpsToolkit
@DevOpsToolkit 3 года назад
I'll check it out. As for the complexity... The simpler something is, the more I like it and want to use it, as long as that something does what I need it to do. I'm not fond of the idea of using something overly complex just in case we might need it one day. On the other hand, whatever I'm using must do what I need it to do, otherwise it does not matter whether it is simple or not. I good example is docker Swarm. I loved it and used it for a long time but, eventually, I had to move everything to k8s simply because it could not do what I needed it to do (apart from being an abandoned project). In any case... Let me check kubewarden and get back to you.
@StieglmaierThomas
@StieglmaierThomas 3 года назад
@@DevOpsToolkit I really like your videos and the way that you present all these topics, they always inspire me to look at my own setup and see what maybe could be done better. Also I agree with a lot of you opinions on how to do things, so that just lets me think that I'm not so far off the correct way ;)
@hennes131
@hennes131 3 года назад
Very good summary and overview. I would love to get your opinion and comparsion of both tools.
@DevOpsToolkit
@DevOpsToolkit 3 года назад
If everything goes as planned, the comparison should be published this Thursday.
@-XSX-
@-XSX- 11 месяцев назад
Amazing, since this video kyverno has added many policies, the number now stands as 292, which satisfies most of the cases..
@DevOpsToolkit
@DevOpsToolkit 11 месяцев назад
Yeah. Kyverno is amazing.
@vn7057
@vn7057 Год назад
Do anyone know 1. What if kyverno itself service down Will the police continue work ? 2. If we use ArgoCD I think it is not good to enable the auto correction by Kyverno otherwise they will keep in to the loop
@DevOpsToolkit
@DevOpsToolkit Год назад
1. If Kyverno controller is down, policies will not work. 2. I do not like Kyverno's ability to modify or create resources at runtime except in very special situation. Now, if you do need to do that you can instruct Argo CD which parts of resources to ignore and those created by Kyverno are not managed by Argo CD so it will not interfere (but will be against GitOps principles).
@squalazzo
@squalazzo 3 года назад
hi Viktor! Which feature is missing in k3d preventing to run kyverno, as you said you had to use kind to test this? thanks!
@DevOpsToolkit
@DevOpsToolkit 3 года назад
Let me reproduce it and get back to you...
@DevOpsToolkit
@DevOpsToolkit 3 года назад
My bad. I did not check the details when it failed in k3d so I cannot say what was wrong at the time. I just tried it again and it works like a charm. I just added the following message to the pinned comment: "I made a mistake in the video by saying that it did not work in k3d. When I tried it again a while later, everything worked like a charm. My guess is that there was a temporary problem or an issue I caused when I was recording the session. In any case, I stand corrected. it works in k3d!!!"
@squalazzo
@squalazzo 3 года назад
@@DevOpsToolkit thank you very much, quick and efficient! 😀
@devendra-tpg
@devendra-tpg 3 года назад
Hi , Can you please let me know if this can used in multicloud environment. Thanks
@DevOpsToolkit
@DevOpsToolkit 3 года назад
Yes it can :) It can run in any k8s cluster anywhere.
@devendra-tpg
@devendra-tpg 3 года назад
@@DevOpsToolkit Would you be able to share some documentation on multicloud. Thanks
@DevOpsToolkit
@DevOpsToolkit 3 года назад
It is essentially the same no matter how many clusters or clouds you have. You just have to install kyverno and apply the policies in each.
@kksaxena1550
@kksaxena1550 3 года назад
Is it similar to RBAC?
@DevOpsToolkit
@DevOpsToolkit 3 года назад
Not much. RBAC is about who can access what while Kyverno, and policies in general, is about who can do what on a more granular level. You can, for example, use RBAC to say "you can create this" but NOT to say "you are not allowed to create this with those parameters or properties".
@VeloBlade
@VeloBlade 2 года назад
which kyverno version did you test here ?
@DevOpsToolkit
@DevOpsToolkit 2 года назад
I do not remember which exact version I used. It was the latest at the time the video was published. Kyverno improved a lot since than.
Далее
AWS Networking Basics For Programmers | Hands On
27:14
Просмотров 127 тыс.
HA-HA-HA 👊  #countryball
00:15
Просмотров 2,7 млн
10 Must-Have Kubernetes Tools
18:53
Просмотров 38 тыс.
Getting Started with Nix
25:49
Просмотров 70 тыс.
What is OpenTelemetry?
12:55
Просмотров 6 тыс.
Easy Kubernetes Using Ansible! (RKE2)
41:12
Просмотров 9 тыс.