Introducing new Kubernetes validation checks or policies against existing configuration often surfaces violations. To address this, an Initiatives workflow was created in ConfigHub that lets teams roll out new policies non-disruptively. Policies start in Warn mode, reporting failures without blocking deployments. Violations can be fixed via ConfigHub functions or direct edits, and once resolved, the policy is promoted to enforced mode. The workflow integrates with Kyverno and Kubernetes ValidatingAdmissionPolicy, and is designed to be extensible across multiple policy tools and CI environments — solving gaps that exist in standard Kyverno CLI and in-cluster admission control workflows.
48 Impressions