Marcio Cunha

GitOps with ArgoCD and Build-Time Security Policy Validation with Kyverno

Learn how to secure Kubernetes clusters by combining continuous delivery via GitOps and automated security policy checks before deployment.

Marcio Cunha•4 min
Also available in:EspañolPortuguês
Summary
  • Continuous synchronization through GitOps eliminates drift between the desired state in the repository and the running cluster.
  • Kyverno intercepts requests and enforces granular security rules based on declarative Kubernetes native patterns.
  • Build-time validation prevents vulnerable configurations from reaching staging or production environments.
  • Strict privilege separation and code-based auditing drastically reduce the risk of human error during deployments.
  • Continuous policy monitoring ensures regulatory compliance without slowing down developer delivery workflows.

The Security Challenge in Modern Kubernetes Environments

Managing multiple infrastructure environments requires rigorous standardization and strict control over what executes on servers. Kubernetes has become the industry standard for managing containers, which are isolated software packages containing an application and everything it needs to run. However, this flexibility introduces inherent risks: misconfigurations or excessive permissions can expose critical security vulnerabilities. Ensuring that every code or infrastructure change passes through a rigorous security gate is the primary challenge for modern engineering teams.

In practice, this means relying solely on manual code reviews or superficial testing is no longer sufficient. When dozens of developers push updates daily, the human factor becomes the weakest link in the security chain. This is precisely where automated approaches come in, capable of intercepting errors before they even reach production servers, ensuring stability and compliance without sacrificing delivery speed.

Understanding the GitOps Concept in Practice

The term GitOps refers to a management methodology where the code repository, typically Git, serves as the single source of truth for infrastructure and software. Instead of administrators executing manual commands directly on servers, every change goes through pull requests, reviews, and versioned history. In practice, an agent installed inside the cluster monitors the repository and automatically adjusts the environment to reflect exactly what is written in the code.

ArgoCD is one of the most popular tools for implementing this philosophy in Kubernetes environments. It continuously compares the actual state of your cluster with the desired state declared in Git configuration files. If someone alters the cluster manually, ArgoCD detects the drift and either reverts the change or alerts the team. This approach brings absolute traceability, allowing any failure to be rolled back in seconds simply by reverting to a previous commit in the Git history.

The Importance of Policy Validation with Kyverno

Automating delivery does not solve security problems if the deployed code contains structural vulnerabilities, such as containers running with administrator privileges or unsigned container images. To solve this, we use policy engines like Kyverno, designed specifically for the Kubernetes ecosystem. Kyverno allows you to define security rules using native Kubernetes resources, removing the need to learn a complex new programming language.

In practice, Kyverno acts as a strict inspector at the cluster entrance gate. It can block the creation of pods that fail to meet corporate guidelines, require all containers to originate from trusted sources, or automatically inject monitoring labels into newly created resources. This verification prevents dangerous configurations from going unnoticed, securing the infrastructure natively and transparently for developers.

Integrating the Delivery Workflow with Early Validation

Pairing ArgoCD with Kyverno creates a double barrier of protection, but the ideal approach is to shift this validation further left in the development cycle, right down to the build and commit phase. When we validate policies before final packaging, we avoid the frustrating cycle of pushing code to the cluster only to discover it was rejected due to a security violation.

To implement this early check, we can use command-line tools that simulate Kyverno rules directly on the developer machine or within continuous integration pipelines. Below is an example of a policy applied via a YAML file to ensure no container runs as the root user, which possesses unlimited operating system permissions:

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: restrict-root-user
spec:
  validationFailureAction: enforce
  rules:
    - name: check-run-as-non-root
      match:
        any:
          - resources:
              kinds:
                - Pod
      validate:
        message: 'Running containers as root is prohibited for security reasons.'
        pattern:
          spec:
            securityContext:
              runAsNonRoot: true

This code block defines a clear rule: any attempt to deploy a pod without the directive preventing the root user will be summarily blocked. This declarative simplicity allows security teams to define corporate standards while software engineers receive immediate feedback on their applications.

Final Considerations and Next Steps

The joint adoption of GitOps with ArgoCD and policy validation via Kyverno represents a mature leap in operational capabilities for any technology organization. By transforming security rules into versioned code, we eliminate ambiguity and ensure compliance is maintained continuously and automatically. The result is a more stable, secure environment prepared to scale without compromising business agility.

To advance on this journey, start by mapping the most critical risks in your current environment and implement restrictive policies gradually, initially using audit mode before enforcing total blocks. This way, your team adapts to new security standards smoothly, building a culture of shared responsibility and technical excellence.