Kyverno
Kyverno is a CNCF Graduated open-source policy engine for Kubernetes that validates, mutates, generates, and cleans up resources using YAML and CEL-based policies, used in production by 1,000+ organizations with commercial support offered via creator Nirmata and ecosystem partners.
- Company typePrivate
- Founded2019
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Kyverno does
Kyverno is a Kubernetes-native policy engine that enables Policy as Code for cloud-native infrastructure. Created in 2019 and donated to the Cloud Native Computing Foundation (CNCF) in 2020, Kyverno graduated from CNCF in March 2026 and is used in production by 1,000+ organizations including Deutsche Telekom, LinkedIn, Bloomberg, Spotify, Adidas, US Department of Defense, and Yahoo. The platform uses Kubernetes-native YAML with Common Expression Language (CEL) for policy definition, allowing operators to validate, mutate, generate, and clean up Kubernetes resources without learning specialized policy languages like Rego. As of February 2026 (Kyverno 1.17), CEL-based policies are stabilized as the primary type, with legacy APIs deprecated. The platform extends beyond admission control to include image verification (Sigstore Cosign, Notary v2), background scanning, and runtime enforcement, plus sub-projects such as the Kyverno CLI (shift-left CI/CD testing), Policy Reporter (compliance dashboards), Kyverno Chainsaw (end-to-end testing), Kyverno Authz Server (Envoy/HTTP authorization), Kyverno Backstage Plugin (developer portal integration), and Kyverno JSON (non-Kubernetes payloads). A library of 640+ pre-built policies is available for common use cases.
Kyverno is governed as a community open-source project under The Linux Foundation/CNCF and does not have traditional venture funding. Commercial revenue is generated indirectly through Nirmata — the creator of Kyverno, which offers Nirmata Enterprise for Kyverno (enterprise-grade policy and governance support) — and through ecosystem partners including Giant Swarm (managed Kubernetes with Kyverno Security Pack), InfraCloud and Blakyaks (consulting and implementation services), and KodeKloud (training). The go-to-market motion is community-led: top-of-funnel adoption occurs through GitHub, CNCF Slack channels (#kyverno, #kyverno-dev), Kubernetes Slack, Google Groups, and weekly community meetings, with mid-funnel conversion through documentation, the policy showcase, and KubeCon presence. Distribution is self-serve via GitHub releases, container images (Docker Hub, ghcr.io), and package managers (Homebrew, Krew, AUR), with enterprise sales executed by partner resellers and SIs. The primary customer segments are enterprise Kubernetes operators (security and compliance enforcement), platform engineering teams (multi-tenancy and self-service), and DevOps/SRE teams (shift-left CI/CD policy testing).
Kyverno firmographics
Firmographics- Name
- Kyverno
- Legal name
- Kyverno
- Website
- https://kyverno.io
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Kyverno is a CNCF Graduated open-source policy engine for Kubernetes that validates, mutates, generates, and cleans up resources using YAML and CEL-based policies, used in production by 1,000+ organizations with commercial support offered via creator Nirmata and ecosystem partners.
- Ownership category
- akta.pro rank
Kyverno industry classification
Industry- Product category
- Kubernetes Policy Engine
- akta.pro primary industry
- Container Platforms & Orchestration (Kubernetes) (HDABADAF)
- akta.pro secondary industries
- Kubernetes & Container Security (KSPM/KCSPM, Runtime) (HDADADAE), Container & Kubernetes Application Security (HDADACAE), Cloud Security for Containers & Kubernetes (KSPM/Kubernetes Security) (HDABAHAO)
Keywords
Where Kyverno is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
Kyverno business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Commercial Support and Services: Kyverno is open-source software, but commercial products and services are offered by ecosystem partners. Nirmata (the creators of Kyverno) offers enterprise-grade policy and governance solutions. Other partners provide consulting, implementation, and training services.
- Enterprise Software (via Partners): Partners like Nirmata and Giant Swarm offer managed services and enterprise products built on Kyverno, providing a revenue path for the ecosystem while Kyverno itself remains open-source.
Go-to-market motion1 record
Distribution channels7 records
Marketing channels7 records
Kyverno product offering
Product offeringCore offering
Kyverno is a Kubernetes-native policy engine that enables Policy as Code for cloud-native infrastructure. It validates, mutates, generates, and cleans up Kubernetes resources using policies written in familiar YAML with Common Expression Language (CEL). The engine operates as an admission controller with background scanning for continuous policy enforcement.
Product overview
Kyverno is a unified Policy as Code platform that provides policy-based security, automation, and governance for cloud-native infrastructure using YAML and CEL-based policies. The core offering is the Kyverno Policy Engine, a Kubernetes-native admission controller with background scanning capabilities for continuous policy enforcement. The platform supports multiple policy types: ValidatingPolicy for validation, MutatingPolicy for modification, GeneratingPolicy for resource creation, DeletingPolicy for cleanup, and ImageValidatingPolicy for supply chain security. Key sub-projects include the Kyverno CLI for local/CI/CD testing, Policy Reporter for compliance reporting with Backstage integration, Kyverno Chainsaw for end-to-end testing, and Kyverno Authz Server for service mesh authorization. The platform provides native image verification using Sigstore Cosign and Notary v2. Kyverno is a CNCF Graduated project created by Nirmata, with commercial offerings including Nirmata Enterprise for Kyverno and Giant Swarm's managed service.
Differentiator
Problem solved
Functional benefit
Brands
- Kyverno CLI: Command Line Interface tool for validating and testing policy behavior to resources prior to adding them to a cluster.
- Kyverno JSON
- Kyverno Authz Server
- Kyverno Chainsaw
- Policy Reporter
- Kyverno Backstage Plugin
Products and services
- Kyverno Policy Engine Kubernetes-native policy engine that enables Policy as Code for cloud-native infrastructure. Uses YAML and CEL-based policies to validate, mutate, generate, and clean up Kubernetes resources. Operates as an admission controller with background scanning for continuous enforcement. Used by organizations running Kubernetes at scale.
- Kyverno CLI Command-line interface for validating and testing policy behavior against resources prior to cluster deployment. Supports apply, test, jp, and create commands. Functions as a kubectl plugin or standalone binary. Enables shift-left policy testing in CI/CD pipelines for developers and platform engineers.
- Policy Reporter Sub-project providing in-cluster management of policy reports with web-based GUI. Stable release as of Kyverno v3. Supports PolicyReports and OpenReports API groups with scalable etcd offload for large clusters. Used by security and compliance teams.
- Kyverno Chainsaw Declarative end-to-end testing framework for Kubernetes controllers. Kyverno v0.2.3. Enables policy authors to develop, test, and validate policies before production deployment.
- Kyverno Authz Server Provides programmable and flexible policy-based authorization for Envoy proxies and HTTP services. Feature state: Alpha (Kyverno v0.4.0). Extends Kyverno policy capabilities to service mesh authorization.
- Kyverno Backstage Plugin Plugin integrating Policy Reporter with Backstage developer portal to provide policy compliance views for entities. Feature state: Beta (Kyverno v2.4.0).
- Kyverno JSON SDK for applying Kyverno policies to non-Kubernetes workloads. Works on any JSON payload outside Kubernetes environments. Feature state: Deprecated.
- Nirmata Enterprise for Kyverno Enterprise-grade policy and governance platform from the creators of Kyverno. Provides commercial support and additional enterprise features for organizations adopting Kyverno.
- Giant Swarm Managed Service Managed Kubernetes platform offered by Giant Swarm with Kyverno included in their Security Pack for enterprise-ready policy enforcement.
- Kyverno Playground Online interactive environment for trying Kyverno policies without local installation. Allows policy experimentation and learning for new users.
Quantifiable outcome
- Organizations migrating from OPA/Gatekeeper to Kyverno report substantial performance improvements
- +1 more outcomes
Companies that use Kyverno
Customer profileNamed customers11 records
Segments3 records
Ideal customer profiles3 records
Kyverno technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability2 records
Feature13 records
Kyverno partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- NirmatacoreNirmata is the creator of Kyverno and offers enterprise-grade policy and governance solutions. They provide commercial products and support for Kyverno, making them the primary strategic partner for enterprise adoption.
- Giant SwarmcoreGiant Swarm offers a managed Kubernetes platform with Kyverno included as part of their Security Pack, enabling customers to use Kyverno policies in a fully managed environment.
- InfraCloudminorInfraCloud is a Kyverno Consulting and Implementation Partner that helps organizations design and deploy Kyverno policies.
- BlakyaksminorBlakyaks provides consulting services to design and deploy Kyverno policies for organizations.
- KodeKloudminorKodeKloud offers hands-on Kubernetes and DevOps training, including courses specifically focused on Kyverno for policy management.
- Argo ProjectcoreKyverno provides extensive integration with Argo CD and Argo Workflows, including policies for Application validation, ApplicationSet management, and AppProject configuration.
- SigstorecoreKyverno integrates with Sigstore Cosign for container image signing and verification, supporting keyless signing with Sigstore's transparency log infrastructure.
- NotarycoreKyverno supports Notary v2 for container image signature verification as an alternative to Sigstore Cosign.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Kyverno competitors and assessment
Company assessmentOthers
- Sigstore: CNCF project for software supply chain signing and verification. Kyverno integrates with Sigstore Cosign for image verification, making Sigstore a key enabling technology partner rather than a direct competitor.
- Nirmata: Creator of Kyverno and primary commercial sponsor offering Nirmata Enterprise for Kyverno. A parent/operator relationship rather than a competitor, but the closest commercial analog for monetizing the Kyverno ecosystem.
Broad incumbents
- Snyk: Large incumbent in developer security with container and Kubernetes policy/security offerings. Competes with Kyverno's supply-chain and image-verification use cases as part of a much broader security portfolio.
- Aqua Security: Established cloud-native security platform covering container, Kubernetes, and supply-chain security. Overlaps with Kyverno's runtime controls and image-verification capabilities, but as a wider security suite.
Direct peers
- OPA Gatekeeper: The Kubernetes-specific admission controller built on OPA. Gatekeeper is Kyverno's closest direct competitor for Kubernetes policy enforcement and the system from which Wayfair and the US DoD migrated to Kyverno.
- Styra: Commercial vendor behind OPA and Gatekeeper, offering enterprise distribution, authoring, and runtime products. Styra is the closest direct commercial peer to Nirmata in the Kubernetes policy space.
- Open Policy Agent (OPA): The leading open-source policy engine that Kyverno is most directly compared against. Both target policy as code for cloud-native workloads, but OPA uses Rego while Kyverno uses YAML and CEL, and OPA covers broader use cases (not only Kubernetes).
Emerging players
- Cloud Custodian: Open-source cloud governance and policy engine focused on public-cloud resources (AWS, Azure, GCP). Overlaps with Kyverno in policy-as-code for cloud infrastructure but targets cloud resources rather than Kubernetes-native workloads.
- Falco (Sysdig): Open-source runtime security and threat detection project for Kubernetes, now under the CNCF. Adjacent to Kyverno's runtime policy controls and background scanning capabilities, with overlap in continuous cluster monitoring.
- Conftest (Open Policy Agent project): OPA-adjacent tool for testing configuration files against Rego policies. Comparable to Kyverno CLI's shift-left policy testing capability, with overlap in CI/CD policy validation use cases.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Kyverno social profiles
Digital presenceKyverno financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kyverno leadership team
Management profileNumber of profiles
Kyverno funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kyverno M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kyverno
What does Kyverno do?
Kyverno is a Kubernetes-native policy engine that enables Policy as Code for cloud-native infrastructure. It validates, mutates, generates, and cleans up Kubernetes resources using policies written in familiar YAML with Common Expression Language (CEL). The engine operates as an admission controller with background scanning for continuous policy enforcement.
Is Kyverno a public or private company?
Kyverno is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Kyverno founded?
Kyverno was founded in 2019. It employs 1 to 10 people.
Where is Kyverno based?
Kyverno is headquartered in San Francisco, United States, in the North America region.
How does Kyverno make money?
Two revenue lines are on record. Commercial Support and Services are the primary driver. The others are enterprise Software (via Partners).
Who are Kyverno's main competitors?
Others on record are Sigstore and Nirmata. Broad incumbents are Snyk and Aqua Security. Direct peers are OPA Gatekeeper, Styra and Open Policy Agent (OPA). Emerging players are Cloud Custodian, Falco (Sysdig) and Conftest (Open Policy Agent project).
Does Kyverno have an API?
Yes. Kyverno offers a CLI-based API for policy management and validation. The CLI can be used as a standalone binary or as a kubectl plugin. Key commands include: apply (for dry-run testing of policies against resources), test (for testing policies against sample resources with declared expected results), jp (for JMESPath query and custom filter testing), and various create commands (cluster-role, exception, metrics-config, test, user-info, values, docs). The CLI supports applying policies to local files, Git repositories, or live Kubernetes clusters. It supports generating policy reports (ClusterPolicyReport/ClusterReport) and working with ValidatingAdmissionPolicy and MutatingAdmissionPolicy native Kubernetes resources. The Kyverno CEL libraries provide custom functions like resource.Get() for external data lookups. Developer documentation is at kyverno.io/docs/kyverno-cli/reference/kyverno.
What industry is Kyverno in?
Kyverno's product category is Kubernetes Policy Engine. Its primary akta.pro industry code is HDABADAF, Container Platforms & Orchestration (Kubernetes), with a secondary code of HDADADAE, Kubernetes & Container Security (KSPM/KCSPM, Runtime).