By Shuting Zhao

Kyverno End User Threat Model and Hardening Guide, by ControlPlane

General Security

ControlPlane and Kyverno

The Kyverno project is excited to announce the publication of the Kyverno End User Threat Model and Hardening Guide, authored by the security experts at ControlPlane.

The report is available to download for free and provides an in-depth analysis of the threats that could affect your Kyverno installation, along with practical, layered mitigations to address them.

Summary of the report

Kyverno functions as a critical security control plane, meaning its operational integrity is inseparable from a cluster's overall security posture. The most significant risks stem from misconfigurations, such as permissive failurePolicy: Ignore settings, weak RBAC, or unverified policy supply chains, rather than software vulnerabilities. These issues can appear across different common deployment patterns, which have been documented in the threat model, so you can best understand how to harden common Kyverno deployments and how a layered approach to mitigations can reduce overall risk.

Who should read it

If you are running Kyverno in production — or planning to — you should absolutely read this report. It establishes a shared baseline for how the community evaluates threats to Kyverno, and it will help direct where the project invests in security improvements going forward.

Acknowledgment

Thank you to ControlPlane for their continued efforts in supporting the security of open source and providing recommendations for deploying Kyverno securely across different environments. Interested in more? Check them out: https://control-plane.io/contact/.

Links