Posted on October 1, 2026 by Koray Oksay | CNCF Ambassador The most popular OPA-based policy tool for Kubernetes is literally called Gatekeeper. Admission controllers block . Kyverno's enforcement setting is validationFailureAction: Enforce , which at least sounds neutral, but the failure mode it describes is still the platform telling a developer no. None of this naming is accidental. It reflects how we collectively think about policy: as gatekeeping.

And I've become convinced that this mental model, more than any tooling choice, is why so many platform teams end up quietly resented by the developers they were built to serve. Here's the pattern: Between my day-to-day work on Kubernetes platforms and the hallway conversations at KubeCon + CloudNativeCon, I've heard enough versions of it that I can basically recite it. A platform team builds the platform. Nobody thinks about policies at this stage. They come later, when security asks. Developers start hitting blocked deployments they don't understand.

The platform team turns into an appeals court, spending its days explaining rejections and granting exceptions. Somewhere around this point, shadow infrastructure appears when a cluster someone spun up "temporarily" has deployments flowing through a side channel that doesn't have the policies yet. The platform team, which was created specifically to remove bottlenecks, has become one. And the frustrating part is that usually the policies themselves were fine. The problem wasn't what the policies said.

It was that the whole setup was designed around the verb deny , which means every single interaction a developer has with policy is friction. I've used the word "guardrails" approvingly in my own writing before, most recently in my post on Kyverno and CEL , where I talked about self-service with guardrails as the goal. What I want to do here is push on that word harder, because I've come to think most teams who say "guardrails" have actually built gates and renamed them. The difference isn't branding. It's measurable, and it shows up in whether developers route around your platform or through it.