
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Sat, 16 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/pod-security-admission/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.en</guid>
    <title>Kubernetes Admission Policies &amp; Security 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.en</link>
    <description>The full topology of Kubernetes security in 2026. Kyverno that became CNCF Graduated in November 2024, Rego-based OPA Gatekeeper, the built-in Validating Admission Policy that went GA in k8s 1.30 (CEL), the alpha Mutating Admission Policy in 1.32, Pod Security Admission replacing PSP, CNCF Graduated Falco, eBPF-based KubeArmor and Cilium Tetragon, Sigstore Policy Controller, Connaisseur, Trivy Operator, Polaris, Goldilocks, Kubescape (ARMO), kube-bench, kube-hunter, kube-score, Checkov — who blocks admission, who watches runtime, who verifies images, plus how Toss, Kakao, and Mercari actually run these stacks.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>kubernetes</category><category>security</category><category>admission-controller</category><category>kyverno</category><category>opa-gatekeeper</category><category>rego</category><category>cedar</category><category>validating-admission-policy</category><category>cel</category><category>pod-security-admission</category><category>falco</category><category>kubearmor</category><category>cilium-tetragon</category><category>ebpf</category><category>sigstore</category><category>cosign</category><category>connaisseur</category><category>trivy-operator</category><category>polaris</category><category>goldilocks</category><category>kubescape</category><category>armo</category><category>kube-bench</category><category>kube-hunter</category><category>checkov</category><category>2026</category><category>deep-dive</category><category>english</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.ja</guid>
    <title>Kubernetes admission policies &amp; セキュリティ 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon 徹底ガイド</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.ja</link>
    <description>2026 年の Kubernetes セキュリティ全体地図。2024 年 11 月に CNCF Graduated になった Kyverno、Rego ベースの OPA Gatekeeper、k8s 1.30 で GA したビルトイン Validating Admission Policy (CEL)、1.32 alpha の Mutating Admission Policy、PSP を置き換えた Pod Security Admission、CNCF Graduated の Falco、eBPF ベースの KubeArmor と Cilium Tetragon、Sigstore Policy Controller、Connaisseur、Trivy Operator、Polaris、Goldilocks、Kubescape (ARMO)、kube-bench、kube-hunter、kube-score、Checkov まで — 誰が admit を止め、誰がランタイムを見て、誰がイメージを検証するのか、Toss・Kakao・メルカリの実例まで一気に整理する。</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>kubernetes</category><category>security</category><category>admission-controller</category><category>kyverno</category><category>opa-gatekeeper</category><category>rego</category><category>cedar</category><category>validating-admission-policy</category><category>cel</category><category>pod-security-admission</category><category>falco</category><category>kubearmor</category><category>cilium-tetragon</category><category>ebpf</category><category>sigstore</category><category>cosign</category><category>connaisseur</category><category>trivy-operator</category><category>polaris</category><category>goldilocks</category><category>kubescape</category><category>armo</category><category>kube-bench</category><category>kube-hunter</category><category>checkov</category><category>2026</category><category>deep-dive</category><category>日本語</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive</guid>
    <title>Kubernetes admission policies &amp; 보안 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon 심층 가이드</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive</link>
    <description>2026년 쿠버네티스 보안의 전체 지형도. 2024년 11월 CNCF Graduated 가 된 Kyverno, Rego 기반 OPA Gatekeeper, k8s 1.30에서 GA 된 빌트인 Validating Admission Policy (CEL), 1.32 alpha 의 Mutating Admission Policy, PSP 를 대체한 Pod Security Admission, CNCF Graduated 가 된 Falco, eBPF 기반 KubeArmor 와 Cilium Tetragon, Sigstore Policy Controller, Connaisseur, Trivy Operator, Polaris, Goldilocks, Kubescape (ARMO), kube-bench, kube-hunter, kube-score, Checkov 까지 — 누가 admit 을 막고 누가 런타임을 보고 누가 이미지를 검증하는가, 토스·카카오·메르카리 사례까지 한 번에 정리한다.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>kubernetes</category><category>security</category><category>admission-controller</category><category>kyverno</category><category>opa-gatekeeper</category><category>rego</category><category>cedar</category><category>validating-admission-policy</category><category>cel</category><category>pod-security-admission</category><category>falco</category><category>kubearmor</category><category>cilium-tetragon</category><category>ebpf</category><category>sigstore</category><category>cosign</category><category>connaisseur</category><category>trivy-operator</category><category>polaris</category><category>goldilocks</category><category>kubescape</category><category>armo</category><category>kube-bench</category><category>kube-hunter</category><category>checkov</category><category>2026</category><category>deep-dive</category>
  </item>

    </channel>
  </rss>
