Kyverno to Gatekeeper Translator
Workflow
INPUT → Parse → Feasibility Check → Generate Rego → Validate → Output Files
Step 1: Receive Policy
Accept via: paste YAML, file path, or URL (use WebFetch).
Step 2: Check Feasibility
| Kyverno Type | Gatekeeper Support | Action |
|---|---|---|
validate.pattern |
Full | Translate |
validate.deny |
Full | Translate |
validate.foreach |
Full | Translate |
validate.anyPattern |
Full | Translate |
validate.cel |
Partial | Recommend VAP |
mutate.* |
Alpha | Keep Kyverno |
generate |
None | Cannot translate |
verifyImages |
None | Use Sigstore |
If unsupported features exist, inform user and ask to proceed with supported parts.
See: references/KYVERNO_TO_GATEKEEPER_MAPPING.md for translation patterns.
Step 3: Generate & Validate Rego
mkdir -p /tmp/claude
# Write policy.rego and input.json
opa eval -d /tmp/claude/policy.rego -i /tmp/claude/input.json "data.{package}.violation" --format pretty
Fix errors and re-validate until passing. Show user the translated Rego.
Step 4: Create Output
TRACE_ID=$(python3 skills/kyverno-to-gatekeeper-translator/scripts/get_trace_id.py 2>/dev/null || echo "no-trace")
OUTPUT_DIR="skills/kyverno-to-gatekeeper-translator/assets/${TRACE_ID}"
mkdir -p ${OUTPUT_DIR}/{constraint-templates,constraints,original-kyverno}
Generate files using templates from references/TEMPLATES.md:
original-kyverno/{name}.yamlconstraint-templates/{name}-template.yamlconstraints/{name}.yamlpolicyGenerator.yamlkustomization.yamlTRANSLATION_REPORT.md
Step 5: Summary
Output: skills/kyverno-to-gatekeeper-translator/assets/{TRACE_ID}/
Deploy directly:
kubectl apply -f constraint-templates/ && kubectl apply -f constraints/
Deploy via RHACM:
kustomize build --enable-alpha-plugins . | kubectl apply -n policies -f -
Key Mappings
| Kyverno | Gatekeeper |
|---|---|
validationFailureAction: Audit |
enforcementAction: dryrun |
validationFailureAction: Enforce |
enforcementAction: deny |
{{request.object.*}} |
input.review.object.* |
exclude.namespaces |
spec.match.excludedNamespaces |
References
references/KYVERNO_TO_GATEKEEPER_MAPPING.md- Translation patterns & operatorsreferences/TEMPLATES.md- Output file templatesreferences/COMMON_POLICY_TRANSLATIONS.md- Complete examples