💻 Coding
Kyverno Policy Checklist from Cluster Notes (No Invented Alert Totals)
Compile a Kyverno policy checklist from pasted cluster notes only. No invented alert totals, deny counts, or cluster ranks. Not a live cluster sync.
0Reviews
Prompt
Act as a Kyverno policy checklist coordinator who only uses pasted cluster notes. You compile a policy checklist the notes already support. You do not invent alert totals, deny counts, admission ranks, or CVE scoreboards. This is not a live Kyverno sync, not OPA Gatekeeper rule merge, and not security scoring advice. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Cluster notes I lock (policy stubs, match cues, action fragments): [ClusterNotes] - Kyverno version or cluster notes I lock: [Version] - Cluster or namespace label I may quote (or UNKNOWN): [ClusterLabel] - Policy labels already present (or UNKNOWN): [PolicyLabels] - Match resource cues already present (or UNKNOWN): [MatchResourceCues] - Validate or mutate action cues already present (or UNKNOWN): [ActionCues] - Severity or review cues already present (or UNKNOWN): [SeverityCues] - Words I must not use: [Banned] - What I must never invent (alert totals, deny counts, admission ranks, CVE scoreboards): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: ClusterNotes nouns, Version, ClusterLabel, PolicyLabels, MatchResourceCues, ActionCues, SeverityCues, Lang. Banner: not security scoring advice; not a live Kyverno sync. Forbidden: invented alert totals, deny counts, admission ranks, CVE scoreboards. 2. Policy checklist: one checkbox row per PolicyLabels entry. Attach only MatchResourceCues and ActionCues named beside that policy in ClusterNotes. Missing cue write NOT IN INPUTS. 3. Severity sketch: for each SeverityCues entry, list policies that name it. Do not invent a 412 deny-total claim if absent. 4. Admission caution block: quote ActionCues only. Gatekeeper packs not in ClusterNotes stay NOT IN INPUTS. 5. Refuse list: inventing 412 alert totals, inventing 99 deny counts, inventing admission rank #1, inventing CVE scoreboards. 6. Compliance pass: quote Banned and Never hits. Cut them. Print policy and match counts from ClusterNotes only. Format as Format. Constraints: - Policy checklist from ClusterNotes only. No invented alert totals. - Honor Version. No emojis. Not a live Kyverno dashboard. Not security scoring advice.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
ClusterNotes: policy label Harbor Require Labels as pasted match Deployment as pasted action Validate as pasted; policy label Quay Block Privileged as pasted match Pod as pasted. Alert invent NONE. Deny invent NONE. Version: Kyverno as pasted (do not invent unreleased AI policy coach) ClusterLabel: Cedar Pier staging as pasted PolicyLabels: Harbor Require Labels as pasted; Quay Block Privileged as pasted. Background Network UNKNOWN. MatchResourceCues: match Deployment as pasted for Harbor Require Labels; match Pod as pasted for Quay Block Privileged. DaemonSet pack UNKNOWN. ActionCues: action Validate as pasted for Harbor Require Labels; Quay Block Privileged action NOT IN INPUTS. SeverityCues: severity Review as pasted for Harbor Require Labels; Quay Block Privileged severity NOT IN INPUTS. Banned: 412 alerts, 99 denies, guaranteed admission rank #1 Never: invent alert totals, invent deny counts, invent admission ranks, invent CVE scoreboards Format: ledger + policy checklist + severity sketch + admission caution + refuse + compliance Lang: English
Example Output
1. Ledger. ClusterNotes: policy label Harbor Require Labels + match Deployment + action Validate; policy label Quay Block Privileged + match Pod. Alert invent NONE. Deny invent NONE. Version Kyverno. ClusterLabel Cedar Pier staging. PolicyLabels Harbor Require Labels; Quay Block Privileged. MatchResourceCues Deployment for Harbor Require Labels; Pod for Quay Block Privileged. ActionCues Validate for Harbor Require Labels; Quay Block Privileged action NOT IN INPUTS. SeverityCues Review for Harbor Require Labels; Quay Block Privileged severity NOT IN INPUTS. Lang English. Banner: not security scoring advice; not a live Kyverno sync. Forbidden: invented alert totals, deny counts, admission ranks, CVE scoreboards, 412 alerts, 99 denies, guaranteed admission rank #1. 2. Policy checklist. [ ] Harbor Require Labels | match Deployment | action Validate as pasted. [ ] Quay Block Privileged | match Pod | action NOT IN INPUTS. Background Network not attached. DaemonSet pack not added. 3. Severity sketch. severity Review | policy Harbor Require Labels as pasted. Quay Block Privileged severity | NOT IN INPUTS. Deny totals NOT IN INPUTS so do not invent 99 denies. Second Review cue not invented. 4. Admission caution. action Validate as pasted for Harbor Require Labels. Quay Block Privileged action NOT IN INPUTS. Gatekeeper pack NOT IN INPUTS. Do not invent CVE packs. 5. Refuse. 412 alert totals: refused. 99 deny counts: refused. admission rank #1: refused. CVE scoreboards: refused. Unreleased AI policy coach: refused. 6. Compliance. Banned hits none. Policies 2. Matches named 2. Format ledger+policy checklist+severity sketch+admission caution+refuse+compliance. Gaps: Quay Block Privileged action, Quay Block Privileged severity, Background Network, DaemonSet pack, deny totals. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.