Kubewarden

C
C tier on Infrastructure Policy as Code ToolsScore 6.7 · #13 of 24
Android app
Not listed
Free plan
No
Runs on
Linux, Mac, self-hosted, Windows
kubewarden.io
The Kubewarden homepage

Summary

Kubewarden is an open-source security platform for Kubernetes workloads, with components that can be used together or independently. Its stable Admission Controller can block unsafe workloads before they enter a cluster. Operators can manage policies as Kubernetes resources, test them in monitor mode before enforcement, and audit workloads with PolicyReports. Policies can use WebAssembly-compatible languages such as Rust, Go, CEL, and Rego, and policies from OPA, Gatekeeper, and ValidatingAdmissionPolicy can be reused. A beta SBOM Scanner finds container-image vulnerabilities and supports VEX to identify findings that do not affect software. The beta Runtime Enforcer controls what can run inside pods. Its experimental Network Enforcer observes traffic and can produce Kubernetes NetworkPolicy or Istio AuthorizationPolicy rules. Policies can be distributed through OCI-compliant registries. Kubewarden is free, and its command-line tool has installation instructions for Linux, macOS, and Windows. The project provides Helm installation instructions and links to community meetings and its Kubernetes Slack community.

Who it is for

Kubewarden suits teams that want Kubernetes policy controls across admission, runtime, software bills of materials, or network activity. Teams can adopt its components separately, and enterprise support is available through SUSE Security Admission Controller.

What is good

  • Stable Admission Controller blocks unsafe workloads.
  • Policies support WebAssembly-compatible languages.
  • Can reuse OPA and Gatekeeper policies.
  • Components can be used independently.
  • Free and open source.

What to know first

  • Network Enforcer is experimental.
  • Runtime Enforcer and SBOM Scanner are beta.
  • Network Enforcer requires Kubernetes 1.30 or newer.

Everything Xiaomi review

Kubewarden: the full review

Kubewarden offers policy management and several layers of Kubernetes workload security, but component maturity differs. Consider the stable Admission Controller separately from beta and experimental components when assessing fit.

Overview

Kubewarden is an open-source security platform for Kubernetes, aimed at teams that want to apply workload policies throughout a cluster’s lifecycle. Its strongest case is the stable Admission Controller; the surrounding security components add useful scope, but are at earlier stages of maturity.

Teams can adopt the components together or independently. Kubewarden is a CNCF Sandbox project, accepted on June 17, 2022, and SUSE offers enterprise support through its curated SUSE Security Admission Controller.

It belongs in Kubernetes Security Software, Cloud Governance Software, and Infrastructure Policy as Code Tools.

Key features

Admission policies and compatibility

The stable Admission Controller blocks unsafe workloads before they enter a cluster. Operators manage policies as Kubernetes resources and can use monitor mode before enforcing them, a practical way to assess policy effects before making them blocking rules. Policies can be written in WebAssembly-compatible languages such as Rust, Go, CEL, and Rego. Support for OPA, Gatekeeper, and ValidatingAdmissionPolicy policies can reduce migration work for teams already using those systems.

Policies can be distributed through OCI-compliant registries, and the audit scanner continuously checks policy enforcement over time. PolicyReports provide workload audit reporting. Testing and CI/CD integration support policy development and delivery, while integrations with OpenTelemetry, Prometheus, Jaeger, and Policy Reporter give operators optional observability paths.

Security across the workload lifecycle

The beta SBOM Scanner finds vulnerabilities in container images running in a cluster and supports VEX, which helps distinguish findings that do not affect the software. KEV and EPSS support is on the way. The beta Runtime Enforcer controls what can run inside Kubernetes pods. Both extend protection beyond admission, but their beta status makes them less suitable as the sole basis for mature production controls.

The experimental Network Enforcer discovers workload network activity and can produce native Kubernetes NetworkPolicy or Istio AuthorizationPolicy rules. It supports Istio ambient, Calico, and Cilium on x86_64 and aarch64 with Kubernetes 1.30 or newer. That narrow compatibility and experimental status make it a cautious choice for teams that need dependable network enforcement today.

Deployment and supply-chain safeguards

Component pages provide Helm installation instructions, and the kwctl CLI has installation instructions for Linux, macOS, and Windows. Kubewarden documents SLSA-based verification and publishes signed artifacts and software bills of materials. These practices help teams assess software provenance, though they do not change the maturity of the individual components.

Pricing

Kubewarden is free and open source, with a free plan. There are no paid Kubewarden tiers to compare. Teams seeking commercial support can turn to SUSE’s SUSE Security Admission Controller, a curated version of Kubewarden with enterprise support; its pricing is custom pricing.

Open monthly community meetings and a Kubernetes Slack community offer project-level support routes. Teams that require a formal enterprise support relationship should weigh SUSE’s offering rather than relying on community channels alone.

Platforms

Kubewarden is listed for Linux, macOS, Windows, and self-hosted environments. The kwctl CLI installation instructions cover Linux, macOS, and Windows, while the components are deployed to Kubernetes using Helm. Network Enforcer use additionally requires one of its supported providers, x86_64 or aarch64, and Kubernetes 1.30 or newer.

Who it's for

Kubewarden suits Kubernetes operators who want policy-as-code controls at admission and value policy reuse, registry-based distribution, audit reporting, and a free open-source platform. It is especially compelling for teams already invested in OPA, Gatekeeper, or ValidatingAdmissionPolicy that want to avoid rewriting policies.

It is a weaker fit for organizations that need every security layer to be stable today, or need broad network-provider compatibility beyond the stated choices. The stable Admission Controller can stand on its own, but beta and experimental components should be evaluated separately rather than treated as equally mature parts of a single dependable suite.

Pros and cons

Pros

  • Stable admission control: blocks unsafe workloads before cluster entry, with monitor mode available before enforcement.
  • Policy portability: supports WebAssembly-compatible languages and reuse of OPA, Gatekeeper, and ValidatingAdmissionPolicy policies.
  • Free and modular: teams can use components independently and avoid paying for a bundled suite.
  • Operational visibility: continuous audit scanning, PolicyReports, and optional observability integrations support ongoing policy oversight.

Cons

  • Uneven maturity: the SBOM Scanner and Runtime Enforcer are beta, while the Network Enforcer is experimental.
  • Network requirements are specific: the Network Enforcer is limited to Istio ambient, Calico, or Cilium, x86_64 or aarch64, and Kubernetes 1.30 or newer.
  • Enterprise support is separate: SUSE’s curated supported version is a distinct route rather than support included with the free project.

Alternatives

Cloud Custodian is another free, open-source option, with an Apache 2.0 license and Linux, macOS, Windows, and self-hosted platforms; consider it when those characteristics suit your governance needs better than Kubewarden’s Kubernetes workload focus.

AWS Control Tower is worth considering for an AWS-oriented setup: it has no additional charge for Control Tower, though underlying AWS services are billed by usage.

OmniGCloud has a free plan with one connector, a single SaaS workspace, basic CSV export, and a basic audit trail; consider it if that starting point fits better than Kubernetes-native policy controls.

CGPulse offers a free plan with two cloud accounts, 10 scans per month, one tracked initiative, five auto-fixes per month, and watermarked PDF reports. Choose it instead when those cloud-account scanning and reporting limits match the task.

CoreStack Cloud Governance offers product, bundle, and assessment options with custom pricing.

Jamcracker is a cloud management platform for MSPs, system integrators, enterprises, and cloud teams working across AWS, Azure, Google Cloud, VMware, and private clouds.

MacroCloud Governance Center is a paid web product with pricing on request.

PolicyCortex is a paid web product with annual or monthly terms and commercial terms on request.

Verdict

Kubewarden is a strong choice for Kubernetes teams that want free, modular policy enforcement and a stable admission layer with broad policy-language and engine compatibility. Its main advantage is policy control without forcing a rewrite or paid platform commitment; its main reason to look elsewhere is the uneven maturity of its broader security layers. Adopt the Admission Controller confidently on its own, and treat beta and experimental components as additions to evaluate against your organization’s risk tolerance.

Compared on infrastructure policy as code tools

Free plan
Yeskubewarden.io

Facts

Product type
Kubewarden is an open source security platform for Kubernetes.kubewarden.io · 1 Oct 2026
Admission control
Its stable Admission Controller stops unsafe workloads before they enter a cluster.kubewarden.io · 1 Oct 2026
SBOM scanning
Its SBOM Scanner is a beta component that finds vulnerabilities in container images running inside a cluster.kubewarden.io · 1 Oct 2026
Runtime enforcement
Its Runtime Enforcer is a beta component that controls what can run inside Kubernetes pods.kubewarden.io · 1 Oct 2026
Network enforcement
Its Network Enforcer is experimental and discovers network activity to secure communication between workloads.kubewarden.io · 1 Oct 2026
Policy languages
Policies can be written in any programming language that generates WebAssembly binaries.docs.kubewarden.io · 1 Oct 2026
Policy reuse
Kubewarden supports reusing policies from other policy engines without rewriting them.docs.kubewarden.io · 1 Oct 2026
Policy distribution
Policies can be distributed through standard OCI-compliant registries.docs.kubewarden.io · 1 Oct 2026
Audit scanner
The audit scanner actively and continuously checks policy enforcement over time.docs.kubewarden.io · 1 Oct 2026
Supply-chain security
Kubewarden documents SLSA-based verification and publishes signed artifacts and software bills of materials.docs.kubewarden.io · 1 Oct 2026
Observability integrations
Optional integrations include OpenTelemetry, Prometheus, Jaeger, and Policy Reporter.docs.kubewarden.io · 1 Oct 2026
Network providers
The Network Enforcer supports Istio ambient, Calico, and Cilium providers on x86_64 and aarch64 architectures with Kubernetes 1.30 or newer.docs.kubewarden.io · 1 Oct 2026
CLI platforms
The kwctl CLI has installation instructions for Linux, macOS, and Windows.docs.kubewarden.io · 1 Oct 2026
Enterprise support
SUSE provides full enterprise support through the SUSE Security Admission Controller, a curated version of Kubewarden.docs.kubewarden.io · 1 Oct 2026
Governance
Kubewarden was accepted into the CNCF Sandbox on June 17, 2022.cncf.io · 1 Oct 2026
Purpose
Kubewarden is an open source security platform for Kubernetes that secures workloads across their lifecycle.kubewarden.io · 2 Oct 2026
Components
Its components are the Admission Controller, Network Enforcer, Runtime Enforcer, and SBOM Scanner, which can be used together or independently.docs.kubewarden.io · 2 Oct 2026
Policy compatibility
The Admission Controller supports reusing OPA, Gatekeeper, and ValidatingAdmissionPolicy policies.kubewarden.io · 2 Oct 2026
Policy operations
Operators can manage policies as Kubernetes resources, use monitor mode before enforcement, and audit workloads with PolicyReports.kubewarden.io · 2 Oct 2026
Network integrations
Network Enforcer works with Calico, Cilium, or Istio Ambient to observe traffic and produce native Kubernetes NetworkPolicy or Istio AuthorizationPolicy rules.kubewarden.io · 2 Oct 2026
Risk context
SBOM Scanner supports VEX to identify findings that do not affect software; its page says KEV and EPSS support is on the way.kubewarden.io · 2 Oct 2026
Deployment
The component pages provide Helm installation instructions for deploying Kubewarden components to Kubernetes.kubewarden.io · 2 Oct 2026
Support
The project offers open monthly community meetings and links to its Kubernetes Slack community.kubewarden.io · 2 Oct 2026
Project status
Kubewarden is a CNCF Sandbox Project; its Admission Controller is marked stable, Runtime Enforcer and SBOM Scanner beta, and Network Enforcer experimental.kubewarden.io · 2 Oct 2026

Best Kubewarden alternatives

See all 12