Guides

Create a protection plan

Freeze chosen changes to an application or namespace for a time window, check that the protection is in force, and read the report.

A protection plan blocks chosen changes for a scope and a time window. This guide sets one up for a release window: audit first, then enforce.

You need: the Contributor role or higher on protection plans, and at least one application on the Applications page. Enforcing on a namespace scope needs the Owner role.

1. Open the form

Open Protection plans and choose Create Plan. Nothing is saved until you submit, so you can move between sections freely.

2. Fill in the details

FieldWhat to enter
NameUnique, ignoring case. Up to 64 characters, no {{ or }}.
DescriptionOne line of context. It appears on the plan page and in reports.
Severity, priorityLabels for people (priority from −100 to 100). They do not change enforcement.
Environment, tagsOptional, for filtering. A plan in Production always requires approval.
ExecutionAutomatic deploys when the plan starts. Requires approval deploys nothing until another user approves. It cannot be changed after creation.

3. Choose the scope

  • Applications: pick one or more discovered applications. The plan covers their workloads in every namespace they span.
  • Namespaces: pick one or more namespaces. The plan covers every resource in them. The release namespace and the excluded namespaces (by default default, kube-system, kube-public and kube-node-lease) cannot be targeted.

Optionally exclude kinds, or, for an application scope, individual resources.

4. Choose the policies and the mode

Pick the mode for the whole plan:

  • Audit records violations and blocks nothing. Use it first.
  • Enforce rejects violating requests at admission.

Then add one or more templates. The picker shows only the templates the scope supports; changing the scope type clears your choices.

TemplateBlocks
block-createCreating any resource in scope
block-updateUpdating any resource in scope
block-deleteDeleting any resource in scope
block-replica-scalingChanging replica counts on Deployments and StatefulSets (applications scope only)
block-image-tagsContainer images with the tags you list
block-image-typesContainer images matching the registry or name patterns you list
block-storage-changesCreating, changing or deleting PersistentVolumeClaims, and volume changes on workloads
block-config-secret-resource-changesUpdating or deleting ConfigMaps and Secrets
block-workload-config-mount-changesChanging workload volume mounts and ConfigMap or Secret sources

To audit some templates and enforce others, create two plans.

5. Set the schedule

  • Time range: the plan activates at the start and terminates at the end, at most one controller tick (31 seconds by default) late.
  • Permanent: runs until you cancel it.

For a release window, pick Time range. To try it out, set a 15-minute window starting now.

Participants is informational. Roles decide who may approve, cancel or reactivate a plan.

6. Submit

Choose Create Plan. You should see the plan in one of these phases:

PhaseMeaning
pending_approvalWaiting for approval. Nothing is deployed.
scheduledApproved or automatic, waiting for the start time.
activePolicies deployed.

A plan that requires approval must be approved by an Owner who did not create or edit it. Approvers are notified in the dashboard and approve from the plan page.

7. Check that the protection is in force

Open the plan. While it is active:

  • Health should read Healthy within one tick: Telark found every expected Kyverno policy, ready and in the right mode. Drifted means a policy was edited; Telark redeploys it on the next tick. Degraded means a policy is missing or not ready; see Troubleshooting.
  • Violations lists every request that broke a rule. In audit mode the message reads "would be blocked".

You can also list the policies yourself:

kubectl get policies.kyverno.io -A -l telark.io/protection-plan=<plan-id>

8. Switch to enforce

When the audit violations match what you expect, edit the plan and change the mode to Enforce. A violating request now fails with the template's message, for example:

Resource deletion is blocked by protection plan "<plan-id>".

9. Read the report

When the window ends the plan moves to terminated, Telark deletes its policies, and a final report appears under Reports (HTML, Markdown, JSON or CSV). You can also generate a report on demand while the plan runs.

Download the report if you need the record: a finished plan shows zero live violations, and the report is where its history lives.

Next

  • Use Duplicate on a finished plan to reuse its settings for the next window.
  • Roll back an application if a change got through before the plan started.
  • Protection plans explains the lifecycle in depth.