問題文
A cluster runs a policy that matches on a wildcard. The team is surprised at how much CPU Kyverno consumes. What does the documentation say about wildcards and sizing?
選択肢
- A wildcard forces Kyverno to process every operation on every resource, so even one simple policy written that way has significant impact.
- Wildcards are rejected by the policy validation webhook in recent versions, so the observed consumption must have another cause and the team should look at the number of policy reports in etcd instead.
- The impact is limited to the admission controller, so raising the memory limit on that Deployment alone resolves the situation without any change to how the policy is written.
- Sizing should be derived from the node or Pod count of the cluster.