Search results for: kyverno


CNCF Welcomes New Silver Members as Enterprises Scale AI From Training to Inference

Posted on September 7, 2026

New members including SoftBank Corp. and Crusoe join the cloud native community to help build cost-efficient, sovereign infrastructure SHANGHAI, China – KubeCon + CloudNativeCon + OpenInfra Summit + PyTorch Conference China 2026 – September 8, 2026…


Building an AI factory on Kubernetes

Posted on August 27, 2026 | Hrittik Roy | CNCF Ambassador and Platform Advocate at vCluster

An AI factory is not just a model or a cluster. It is a pool of GPUs that many teams draw from at once: one team fine-tuning, another serving inference, a third running evaluations, all on…


Eleven minutes, zero humans: Building a self-healing Kubernetes upgrade pipeline on Kairos

Posted on August 14, 2026 | Olivier Calzi | CNCF Golden Kubestronaut

Once upon a time, upgrading a Kubernetes control plane meant staying awake for it. SSH into every node. Run the upgrade by hand. Watch etcd health the whole time, hoping quorum holds through every reboot. This…


Good apps aren’t born, they’re guided: Building observable policy as code

Posted on August 12, 2026 | Diana Todea (Head of Developer Relations Engineering, VictoriaMetrics) & Cortney Nickerson (Community at Kyverno)

As parents in tech, we’ve learned that neither children nor applications thrive without clear boundaries. There are no “good” or “bad” kids, just as there are no inherently “good” or “bad” applications, only behaviors shaped by…


Shadow AI in CI/CD: Threat-modeling the path from developer laptop to Kubernetes

Posted on August 7, 2026 | Matteo Bisi, ReeVo SpA

Artificial intelligence is becoming part of daily software delivery, often before it becomes part of the security architecture. That gap has a name: Shadow AI. It is any AI tool, model, agent, extension, or integration used…


Runtime Supply Chain Verification using the Node Resource Interface (NRI)

Posted on July 30, 2026 | Sascha Grunert

The widely used container supply chain verification tools today operate at the Kubernetes API layer as admission webhooks (such as Kyverno, OPA Gatekeeper, and Sigstore Policy Controller). They intercept pod creation, check signatures and attestations, and…


Confidential Containers becomes a CNCF incubating project

Posted on July 22, 2026 | CNCF Staff

The CNCF Technical Oversight Committee (TOC) has voted to accept Confidential Containers as a CNCF incubating project. About Confidential Containers Confidential Containers addresses the need to protect data in use within cloud native environments. While data…


I made a policy engine think it was in production

Posted on July 22, 2026 | Sargam Puram, Kyverno Project Maintainer

Kyverno is a Kubernetes-native policy engine that validates, mutates, and generates resources before workloads reach your cluster, enforcing security and compliance rules as code, without requiring a separate policy language. Enterprise teams running Kyverno policies in…


How data sovereignty is changing cloud native infrastructure design

Posted on July 3, 2026 | Dana Cazacu, Marketing Manager, VEXXHOST

The core issue isn’t where your server sits. It’s who can be compelled to hand over what’s on it. For years, cloud providers treated sovereignty as a geography problem. Pick a region. Choose a country. Keep…


Slam26 Spring Transparency Report

Posted on July 1, 2026

Setting the stage for the Spring 2026 Security Slam The CNCF Security Slam has continuously evolved to meet the community’s need for robust software supply chain security. In 2022 and 2023, the event functioned as highly…