DevConf.IN 2025

Aftab S

Aftab is a DevOps Engineer specializing in cloud-native solutions, with expertise in AWS, Azure, and containerization technologies like Docker and Kubernetes. Skilled in Observability, he improves system reliability and performance using tools like Prometheus, Grafana, Loki, Datadog, and OpenTelemetry. Additionally, he is also an active speaker who shares his knowledge at tech events and various workshops.


Company or affiliation

Abilytics Inc.

Job title

DevOps Engineer


Session

02-28
14:30
35min
Enforcing Security and Compliance with Kubernetes Policy Engines
Aftab S

Imagine a DevOps team managing a Kubernetes cluster. On a Friday, Alex, an intern, deploys a new app to the Kubernetes cluster but forgets essential labels, resource limits, and annotations. By Monday, the cluster is chaotic-misbehaving workloads, scattered resources, and a flood of alerts. After troubleshooting, the team finds Alex's oversight and the urgent need for proper rules and checks. This is where Policy engines step in. They act as the 'responsible adults,' enforcing rules to prevent such chaos and streamline operations. In this session, we’ll explore how policy engines enforce Kubernetes security and governance. We’ll compare Open Policy Agent (OPA), Kyverno, and jsPolicy, focusing on their features like validation, mutation, and compliance enforcement. Attendees will also learn how to get started with these tools and select the best policy engine to meet specific needs and enhance their Kubernetes environment.

This talk explores the importance of policy engines in Kubernetes security and compares three popular options: OPA, Kyverno, and jsPolicy. (Will be focusing more on Kyverno and jsPolicy) The abstract highlights:

The role of policy engines in enforcing rules and best practices within Kubernetes clusters
Key functionalities like validation, mutation, and compliance enforcement.
Brief descriptions of OPA, Kyverno, and jsPolicy, emphasizing their unique strengths.
Factors to consider when selecting the right policy engine for your needs.
This presentation will benefit developers and operations professionals seeking to enhance the security and governance of their Kubernetes environments.

Security and Sustainable Computing
Shivneri Room (Chanakya Building / School of Business)