Reference
Policy templates
The nine built-in templates a protection plan can use, with the kinds, operations and parameters each one renders.
A protection plan selects templates by id in spec.policies[].templateID.
Discovery renders each selected template into one namespaced Kyverno
Policy per scope namespace. GET /api/v1/policytemplates returns this
catalog. How plans use templates is explained in
Protection plans.
Catalog
| ID | Code | Name | Operations | Kinds | Scopes | Parameters |
|---|---|---|---|---|---|---|
block-create | bc | Block Resource Creation | CREATE | Every kind | applications, namespaces | none |
block-update | bu | Block Resource Updates | UPDATE | Every kind, plus the /scale subresource of Deployment, StatefulSet, ReplicaSet and ReplicationController | applications, namespaces | none |
block-delete | bd | Block Resource Deletion | DELETE | Every kind | applications, namespaces | none |
block-image-types | bit | Block Image Patterns | CREATE, UPDATE | Deployment, StatefulSet, DaemonSet, Job, CronJob | applications, namespaces | imagePatterns (required) |
block-image-tags | bitg | Block Image Tags | CREATE, UPDATE | Deployment, StatefulSet, DaemonSet, Job, CronJob | applications, namespaces | tags (required) |
block-replica-scaling | brs | Block Replica Scaling | UPDATE | Deployment, StatefulSet and their /scale | applications | none |
block-storage-changes | bsc | Block Storage Changes | CREATE, UPDATE, DELETE on PVCs; UPDATE of workload volumes | PersistentVolumeClaim, workloads | applications, namespaces | none |
block-config-secret-resource-changes | bcsr | Block ConfigMap and Secret Changes | UPDATE, DELETE | ConfigMap, Secret | applications, namespaces | none |
block-workload-config-mount-changes | bwcm | Block Workload Config Mount Changes | UPDATE | Workloads: volumeMounts, ConfigMap and Secret volumes, envFrom, configMapKeyRef and secretKeyRef in every container list | applications, namespaces | none |
Parameters
Parameters are string arrays. Every entry must match the pattern; an unknown parameter is refused.
| Template | Key | Pattern | Example |
|---|---|---|---|
block-image-types | imagePatterns | One glob per entry, no whitespace (^\S+$) | */untrusted-repo/* |
block-image-tags | tags | Docker tag grammar (^[A-Za-z0-9_][A-Za-z0-9_.-]{0,127}$) | latest, dev, snapshot |
block-image-tags matches the parsed image tag. An image pinned by
digest has no tag and is not matched.
What every rendered policy shares
| Property | Value |
|---|---|
| Kind | Kyverno Policy (namespaced, never ClusterPolicy) |
| Name | telark-<plan id>-<template code>-<8 hex of sha256(namespace + application ids)> |
| Labels | telark.io/protection-plan=<plan id>, telark.io/template-id=<id>, app.kubernetes.io/managed-by=telark |
| Annotations | telark.io/plan-name, telark.io/created-by, telark.io/render-hash |
validationFailureAction | Audit or Enforce, from the plan's mode |
| Message | Names the plan id, for example Resource deletion is blocked by protection plan "<id>".; audit mode reads "would be blocked" |
allowExistingViolations | false, so a workload that already violates a rule cannot keep changing during the window |
| Applied with | Server-side apply, field manager telark-protection-plans |
Scope and exemptions
- Applications scope: rules match the application's own resources by
name, per namespace.
block-createalso matches new resources that carry the application's identity label, so a resource joining the app is blocked too.block-storage-changesmatches PVCs by the claim names the workloads reference. - Namespaces scope: rules match every resource of the listed kinds in the namespace.
- Exclusions: the plan's excluded kinds and resources are added to
every rule's exclude list; an excluded kind or resource also excludes
its
/scalesubresource. - Kyverno's own
Policy,PolicyReportandEphemeralReportwrites are always exempt.block-create,block-updateandblock-deletealso exempt the Kubernetes controller manager, the scheduler andkube-systemservice accounts, so replacement Pods and rollout ReplicaSets keep working during a freeze. - CronJobs are evaluated at their own pod-template path.