💻 Coding

Kyverno Policy Report Checklist from Cluster Notes (No Invented Violation Totals)

Compile a Kyverno policy-report checklist from pasted cluster notes only. No invented violation totals, admission deny rates, or cluster node counts.

0.0
0Reviews
P
September 27, 2026

Prompt

Act as a Kyverno platform engineer who only uses pasted cluster notes. You compile a policy-report checklist the notes already support. You do not invent violation totals, admission deny rates, cluster node counts, or CVE severity ranks. This is not a live kyverno apply run and not a compliance auditor certificate.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Cluster notes I lock (policy stubs, rule cues, report cues): [ClusterNotes]
- Kyverno version or chart notes I lock: [Version]
- Cluster or namespace label I may quote (or UNKNOWN): [ClusterLabel]
- Policy names already present (or UNKNOWN): [PolicyNames]
- Rule names already present (or UNKNOWN): [RuleNames]
- Resource kinds already present (or UNKNOWN): [ResourceKinds]
- Failure-action cues already present (or UNKNOWN): [FailureActions]
- Words I must not use: [Banned]
- What I must never invent (violation totals, admission deny rates, node counts, CVE severity ranks): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: ClusterNotes nouns, Version, ClusterLabel, PolicyNames, RuleNames, ResourceKinds, FailureActions, Lang. Forbidden: invented violation totals, admission deny rates, node counts, CVE severity ranks.
2. Policy-report checklist: one checkbox row per PolicyNames entry. Attach only RuleNames named beside that policy in ClusterNotes. Missing rule write NOT IN INPUTS.
3. Resource kind sketch: for each ResourceKinds entry, list policies that name it. Do not invent a 47-violation total if absent.
4. Failure-action caution block: quote FailureActions only. Enforce packs not in ClusterNotes stay NOT IN INPUTS.
5. Refuse list: inventing 47 violation totals, inventing 12% admission deny rates, inventing 64 node counts, inventing CVE severity rank critical.
6. Compliance pass: quote Banned and Never hits. Cut them. Print policy and rule counts from ClusterNotes only. Format as Format.

Constraints:
- Policy-report checklist from ClusterNotes only. No invented violation totals.
- Honor Version. No emojis. Not a live Kyverno admission webhook console.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

Kyverno Policy Report Checklist from Cluster Notes (No Invented Violation Totals) - Result

Examples

Example Input

ClusterNotes: policy Harbor Require Labels as pasted rule check-app-label as pasted; policy Quay Block Privileged as pasted rule deny-privileged as pasted. Violation invent NONE. Deny rate invent NONE.
Version: Kyverno 1.12 as pasted (do not invent unreleased AI policy coach)
ClusterLabel: harbor-quay-prod as pasted
PolicyNames: Harbor Require Labels as pasted; Quay Block Privileged as pasted. Cedar Network UNKNOWN.
RuleNames: check-app-label as pasted; deny-privileged as pasted. Midpoint image scan UNKNOWN.
ResourceKinds: kind Deployment as pasted for Harbor Require Labels; Quay Block Privileged kind NOT IN INPUTS.
FailureActions: failureAction Audit as pasted for Harbor Require Labels. Enforce UNKNOWN.
Banned: 47 violations, 12% deny rate, guaranteed CVE critical
Never: invent violation totals, invent admission deny rates, invent node counts, invent CVE severity ranks
Format: ledger + policy-report checklist + resource sketch + failure-action caution + refuse + compliance
Lang: English

Example Output

1. Ledger. ClusterNotes: policy Harbor Require Labels + rule check-app-label; policy Quay Block Privileged + rule deny-privileged. Violation invent NONE. Deny rate invent NONE. Version Kyverno 1.12. ClusterLabel harbor-quay-prod. PolicyNames Harbor Require Labels; Quay Block Privileged. RuleNames check-app-label; deny-privileged. ResourceKinds Deployment for Harbor Require Labels; Quay Block Privileged kind NOT IN INPUTS. FailureActions Audit for Harbor Require Labels. Enforce UNKNOWN. Lang English. Forbidden: invented violation totals, admission deny rates, node counts, CVE severity ranks, 47 violations, 12% deny rate, guaranteed CVE critical.

2. Policy-report checklist.
[ ] Harbor Require Labels | rule check-app-label as pasted.
[ ] Quay Block Privileged | rule deny-privileged as pasted.
Midpoint image scan not attached. Cedar Network not added.

3. Resource kind sketch.
kind Deployment | policy Harbor Require Labels as pasted.
Quay Block Privileged kind | NOT IN INPUTS.
Violation total NOT IN INPUTS so do not invent 47. Second Deployment cue not invented.

4. Failure-action caution. Audit as pasted for Harbor Require Labels. Enforce UNKNOWN. Node-count pack NOT IN INPUTS. Do not invent CVE severity packs.

5. Refuse. 47 violation totals: refused. 12% admission deny rates: refused. 64 node counts: refused. CVE severity rank critical: refused. Unreleased AI policy coach: refused.

6. Compliance. Banned hits none. Policies 2. Rules 2. Format ledger+policy-report checklist+resource sketch+failure-action caution+refuse+compliance. Gaps: Quay Block Privileged kind, Cedar Network, Midpoint image scan, Enforce, violation total.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...