Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If a Kyverno policy with wildcard kind matching is already active when you install a new Kubernetes CustomResourceDefinition (CRD), a request to create that CRD’s custom resource may be rejected while Kyverno’s resource-discovery view is still catching up. In GitHub issue #10729, the reporter said waiting for the observed refresh or restarting Kyverno restored recognition. That is a report about a particular setup—not a guarantee about every Kyverno release. Read the issue report.

First check what “wildcard guardrail” means

Inspect the policy before troubleshooting. A wildcard in match.resources.kinds tells Kyverno to select resource kinds broadly. A policy that prohibits wildcard permissions in an RBAC Role or ClusterRole is a different configuration: it governs permissions in RBAC rules, not which resource kinds a Kyverno policy selects.

Kyverno documents wildcard kind formats including *, */Kind, Group/*/Kind, and Group/*/*. Its separate policy-library example addresses wildcard entries in RBAC resources lists. Kyverno: Selecting Resources · Policy example: disallow wildcard entities.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the reported failure looks like

In issue #10729, a CRD had been installed after Kyverno was running, and Kubernetes showed the CRD in the cluster. But when the reporter tried to create a corresponding custom resource, Kyverno could not find the resource mapping and the request was rejected as an unknown resource. The report links this mismatch to Kyverno’s cached discovery view: Kubernetes knew about the CRD, while Kyverno had not yet recognized its group, version, and kind.

The reporter observed a 15-minute resource-discovery cache refresh interval in the code context examined for that issue. This is an issue-specific observation from 2024, not a current, universal refresh interval or service-level guarantee for Kyverno. Behavior and timing may differ by release and installation.

How to troubleshoot without guessing

  1. Capture the exact context. Record the Kyverno and Kubernetes versions, installation method, which Kyverno controller handles admission, the full rejection, and relevant controller logs. The issue describes a particular version and setup, so matching the symptom matters.
  2. Inspect the policy match block. Check whether match.resources.kinds uses * or another wildcard pattern. If the policy instead blocks wildcard values in RBAC rules, investigate that policy’s matching and denial separately.
  3. Verify the served resource identity. Confirm the CRD is established, the intended version is served, and the custom resource request uses the expected group, version, and kind (GVK). A visible CRD does not by itself establish that Kyverno has refreshed its discovery mapping.
  4. Consider narrowing the match. If the policy does not need to apply to every eligible resource kind, test an explicit group, version, and kind scope. Kyverno cautions that wildcard kind selection can increase processing because it can send every eligible resource type to the engine.
  5. Retest against the deployed version. If the failure matches issue #10729, waiting for discovery to refresh or rolling Kyverno after the CRD was installed were reported workarounds. Check logs and retry before treating a restart as the fix; a restart is an operational workaround, not proof of root cause.

Choose between broad coverage and operational predictability

The right choice depends on how much coverage the policy needs and how your cluster handles CRD changes. The issue report and Kyverno’s documentation support these trade-offs; they do not establish current refresh timing for every deployment.

Approach Policy coverage Recognition of a newly added CRD Processing and operational trade-off
Keep a wildcard kind match Broad; can select every eligible resource type. The issue report describes a delay until discovery refreshed in the reporter’s setup. Kyverno warns that broad matching can increase processing. Confirm the behavior and timing in your release.
Use explicit group, version, and kind values Limited to the kinds listed in the policy. A newly introduced kind must be covered by the policy’s configured scope; the issue report does not establish a refresh time for this option. Reduces unnecessary broad selection when full coverage is not needed, but requires policy maintenance as resource kinds change.
Wait for discovery or roll Kyverno after CRD installation Does not change the policy’s configured scope. Waiting or restarting reportedly restored recognition in issue #10729. Waiting avoids a restart but may delay use of the resource; a rollout has operational cost and should be validated rather than assumed necessary.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why wildcard matching deserves care

Kyverno’s “Selecting Resources” documentation says: “This type of matching should be used sparingly and carefully as it will instruct the API server to send every eligible resource type to Kyverno, greatly increasing the amount of processing performed by Kyverno.” Use the narrowest explicit scope that meets the policy’s purpose. Kyverno documentation: Selecting Resources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For additional context, Kyverno uses CRDs for its own policy definitions, reports, and other types. Its resource-definition documentation points to kubectl explain for inspecting installed Kyverno types; that background does not confirm whether a particular release has the discovery behavior reported in issue #10729. Kyverno resource definitions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.