k8s-secure-supply-chain, a kind-based reference build, uses five Kyverno checks to refuse at admission any image that CI did not sign and attest. Its author argues that CI scans and signatures stay advisory until the cluster enforces them.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence50
The GitOps tooling worked, and seven services still went back to Docker Compose in a day, because the operator consumes every one of those images and cuts release tags for none of them.
Reality
- Evidence45
- Adoption12
- Hype gap+15
- Incentives30
- Confidence55
AWS EBS volumes are zonal, so a StatefulSet pod can only run in the zone that holds its disk. An admission policy reads that zone and places eligible stateless pods beside it, for a claimed saving above 10%.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives30
- Confidence55
A dev.to writeup puts 30-50% savings in a cleanup phase most teams skip. That number is a share of wasted spend, not of the invoice, and the arithmetic matters before you promise finance anything.
Reality
- Evidence26
- Adoption
- Insufficient
- Hype gap+44
- Incentives48
- Confidence57
A CNCF blog post argues Kyverno gets filed as an admission gate and then run at a quarter of its capacity. The teams getting returns are platform teams, not security teams.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+22
- Incentives58
- Confidence41
A CNCF blog account reports a self-upgrading K3s control plane on Kairos with etcd quorum intact. The instructive part is that both bugs were in the automation, not the OS.
Reality
- Evidence42
- Adoption16
- Hype gap+32
- Incentives64
- Confidence52