Reference

Policy templates

The nine built-in templates a protection plan can use, with the kinds, operations and parameters each one renders.

A protection plan selects templates by id in spec.policies[].templateID. Discovery renders each selected template into one namespaced Kyverno Policy per scope namespace. GET /api/v1/policytemplates returns this catalog. How plans use templates is explained in Protection plans.

Catalog

IDCodeNameOperationsKindsScopesParameters
block-createbcBlock Resource CreationCREATEEvery kindapplications, namespacesnone
block-updatebuBlock Resource UpdatesUPDATEEvery kind, plus the /scale subresource of Deployment, StatefulSet, ReplicaSet and ReplicationControllerapplications, namespacesnone
block-deletebdBlock Resource DeletionDELETEEvery kindapplications, namespacesnone
block-image-typesbitBlock Image PatternsCREATE, UPDATEDeployment, StatefulSet, DaemonSet, Job, CronJobapplications, namespacesimagePatterns (required)
block-image-tagsbitgBlock Image TagsCREATE, UPDATEDeployment, StatefulSet, DaemonSet, Job, CronJobapplications, namespacestags (required)
block-replica-scalingbrsBlock Replica ScalingUPDATEDeployment, StatefulSet and their /scaleapplicationsnone
block-storage-changesbscBlock Storage ChangesCREATE, UPDATE, DELETE on PVCs; UPDATE of workload volumesPersistentVolumeClaim, workloadsapplications, namespacesnone
block-config-secret-resource-changesbcsrBlock ConfigMap and Secret ChangesUPDATE, DELETEConfigMap, Secretapplications, namespacesnone
block-workload-config-mount-changesbwcmBlock Workload Config Mount ChangesUPDATEWorkloads: volumeMounts, ConfigMap and Secret volumes, envFrom, configMapKeyRef and secretKeyRef in every container listapplications, namespacesnone

Parameters

Parameters are string arrays. Every entry must match the pattern; an unknown parameter is refused.

TemplateKeyPatternExample
block-image-typesimagePatternsOne glob per entry, no whitespace (^\S+$)*/untrusted-repo/*
block-image-tagstagsDocker tag grammar (^[A-Za-z0-9_][A-Za-z0-9_.-]{0,127}$)latest, dev, snapshot

block-image-tags matches the parsed image tag. An image pinned by digest has no tag and is not matched.

What every rendered policy shares

PropertyValue
KindKyverno Policy (namespaced, never ClusterPolicy)
Nametelark-<plan id>-<template code>-<8 hex of sha256(namespace + application ids)>
Labelstelark.io/protection-plan=<plan id>, telark.io/template-id=<id>, app.kubernetes.io/managed-by=telark
Annotationstelark.io/plan-name, telark.io/created-by, telark.io/render-hash
validationFailureActionAudit or Enforce, from the plan's mode
MessageNames the plan id, for example Resource deletion is blocked by protection plan "<id>".; audit mode reads "would be blocked"
allowExistingViolationsfalse, so a workload that already violates a rule cannot keep changing during the window
Applied withServer-side apply, field manager telark-protection-plans

Scope and exemptions

  • Applications scope: rules match the application's own resources by name, per namespace. block-create also matches new resources that carry the application's identity label, so a resource joining the app is blocked too. block-storage-changes matches PVCs by the claim names the workloads reference.
  • Namespaces scope: rules match every resource of the listed kinds in the namespace.
  • Exclusions: the plan's excluded kinds and resources are added to every rule's exclude list; an excluded kind or resource also excludes its /scale subresource.
  • Kyverno's own Policy, PolicyReport and EphemeralReport writes are always exempt. block-create, block-update and block-delete also exempt the Kubernetes controller manager, the scheduler and kube-system service accounts, so replacement Pods and rollout ReplicaSets keep working during a freeze.
  • CronJobs are evaluated at their own pod-template path.