Kyverno Threat Model

Posted on 30 July 2026

As part of a continued partnership between ControlPlane and the CNCF, building on top of the threat modelling work done on the cert-manager project, Sam Holmes and I next worked on a threat model for the Kyverno project.

This threat model was slightly different from the cert-manager threat model, we usually performed these threat models entirely “on paper” however for Kyverno, ControlPlane permitted me to use some of my R&D Research time to perform a more thorough analysis of a potential SSRF finding in the Kyverno. As will be detailed in a further blog post, this resulted in some internal vulnerability disclosure with the Kyverno team.

Kyverno is an extremely important part of any K8s deployment as it acts as the security gatekeeper for all K8s resources. In this threat model, we really wanted to highlight on how if misused by a internal attacker, or if the polices delivery method was comprised it can lead to a wide range of security issues which may not be immediately obvious.

In total, 13 different threats were identified and documented along with mitigation recommendations.

Site Build:
2026-08-21:17:55:38.111
Loading page hits...
🐾 Copyright (C) Tom Cope 2020 - 2026 | All Rights Reserved 🏳️‍🌈
GDPR Notice - This Website does not use cookies.