Skip to content

Kubewarden is a policy engine for Kubernetes. It helps with keeping your Kubernetes clusters secure 🔐 and compliant ✔.

Kubewarden policies can be written using regular programming languages or Domain Specific Languages (DSL).

Policies are compiled into WebAssembly modules that are then distributed using traditional container registries.

Getting Started 📚

Check our first-stop kubewarden/community 👋 repository for information about the organization of the project.

Take a look at our documentation 📖 Stay up to date by reading our official blog 📣 and by following us on Twitter.

Get in touch with us on Slack: join the kubewarden channel hosted by the official Kubernetes workspace 👨‍💻 💬 👩‍💻

Enforcing Policies 🔒

Discover ready to use policies by visiting ArtifactHub 📦

Don't forget to take a look at kwctl, our handy multi-purpose tool for managing policies 🛠️ 🧰

Writing policies 📝

Interested in writing a new policy?

Kubewarden allows you to write policies using a variety of programming languages, including Rust, Go, Rego, CEL and others.

These are some useful resources to get you started:

Useful GitHub tags :octocat: 🏷️

Use these tags to find repositories over all GitHub 🗺️ 🌌

Purpose Tag
Policy Template kubewarden-policy-template
Policy kubewarden-policy
Policy SDK kubewarden-policy-sdk

Contributing 🙌

That's fantastic news! 🥳

Check our general CONTRIBUTING.md docs.

Quick links to "core" projects:

Project Scope Language
kubewarden-controller Kubernetes integration point Go
policy-server Run Kubewarden policies Rust
kwctl Kubewarden policy multi-purpose cli tool Rust

Pinned Loading

  1. kwctl kwctl Public

    Go-to CLI tool for Kubewarden users

    Rust 76 16

  2. policy-server policy-server Public

    Webhook server that evaluates WebAssembly policies to validate Kubernetes requests

    Rust 142 18

  3. kubewarden-controller kubewarden-controller Public

    Manage admission policies in your Kubernetes cluster with ease

    Go 197 33

  4. rust-policy-template rust-policy-template Public

    A Kubewarden rust policy template to be used with cargo-generate

    Rust 9 6

  5. go-policy-template go-policy-template Public template

    A template repository to quickly scaffold a Kubewarden policy written with Go language

    Go 10 16

  6. swift-policy-template swift-policy-template Public template

    A template repository to quickly scaffold a Kubewarden policy written with Swift language

    Swift 1 1

Repositories

Showing 10 of 96 repositories
  • policy-evaluator Public

    Crate used by Kubewarden that is able to evaluate policies with a given input, request to evaluate and settings.

    kubewarden/policy-evaluator’s past year of commit activity
    Rust 15 Apache-2.0 8 22 0 Updated Jan 8, 2025
  • kubecon-24-eu-kubewarden Public

    Experiment for Kubewarden booth at Kubecon EU 2024

    kubewarden/kubecon-24-eu-kubewarden’s past year of commit activity
    JavaScript 2 Apache-2.0 2 1 22 Updated Jan 8, 2025
  • deprecated-api-versions-policy Public

    A Kubewarden Policy that detects usage of deprecated and dropped Kubernetes resources

    kubewarden/deprecated-api-versions-policy’s past year of commit activity
    Rust 15 Apache-2.0 4 1 0 Updated Jan 8, 2025
  • github-actions Public

    GitHub actions used by the Kubewarden project

    kubewarden/github-actions’s past year of commit activity
    4 Apache-2.0 7 4 (1 issue needs help) 0 Updated Jan 8, 2025
  • rancher-kubectl-builder Public

    Workflow to rebuild and sign rancher/kubectl image

    kubewarden/rancher-kubectl-builder’s past year of commit activity
    Shell 1 2 1 2 Updated Jan 8, 2025
  • audit-scanner Public

    Reports evaluation of existing Kubernetes resources with your already deployed Kubewarden policies.

    kubewarden/audit-scanner’s past year of commit activity
    Go 8 Apache-2.0 8 9 0 Updated Jan 8, 2025
  • docs Public

    Kubewarden's documentation

    kubewarden/docs’s past year of commit activity
    MDX 13 CC-BY-4.0 23 15 1 Updated Jan 8, 2025
  • pod-privileged-policy Public

    A Kubewarden Policy that limits the ability to create privileged containers

    kubewarden/pod-privileged-policy’s past year of commit activity
    Rust 8 Apache-2.0 6 2 0 Updated Jan 8, 2025
  • kwctl Public

    Go-to CLI tool for Kubewarden users

    kubewarden/kwctl’s past year of commit activity
    Rust 76 Apache-2.0 16 21 (3 issues need help) 0 Updated Jan 8, 2025
  • kubewarden.io Public

    Kubewarden website

    kubewarden/kubewarden.io’s past year of commit activity
    SCSS 11 15 8 0 Updated Jan 8, 2025