Kyverno threat model: the defaults that make enforcement optional

Fail open, by default Audit mode is not enforcement PolicyException: the quiet bypass Kyverno doesn’t watch its own namespace What Kyverno can never protect Sign and verify, not either Turning the admission controller into an SSRF probe Summary Kyverno released a threat model and hardening guide in April 2026, produced by the security consultancy ControlPlane in partnership with the CNCF and reviewed by Kyverno’s own maintainers (Jim Bugwadia and Shuting Zhao among them)....

September 9, 2026 · 13 min · Oleksandr Kulbida