Session
Policy as Code at Workday: Testing and enforcing policies in Workday’s kubernetes distro
At Workday, we are building our next-generation platform on Kubernetes on OpenStack to host Workday microservices. Running a shared Kubernetes distribution means you own the governance layer. We built this layer using Kyverno and discovered that enforcement is harder than writing the policies.
This talk covers our journey: from evaluating options to designing a policy framework to enforcement. We will walk through the entire process, the challenges we faced, and how we balanced friction against enforcement.
We will show how policy guardrails create real friction between platform and product teams; tightening controls improves security, isolation but slows down teams including platform team(thats us); operators managed workloads often need different rules than stateless apps. We will share how we navigated this tension, when to hold the line, when to make exceptions, and how we separated exceptions from habits teams did not want to break.
Shatadru Bandyopadhyay
Senior Software Development Engineer at Workday
Dublin, Ireland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top