Skip to content

Add kyverno built-in toolset support - #1950

Open
mailprak wants to merge 4 commits into
HolmesGPT:masterfrom
mailprak:feature/kyverno-tool-integration
Open

mailprak wants to merge 4 commits into
HolmesGPT:masterfrom
mailprak:feature/kyverno-tool-integration

Conversation

@mailprak

@mailprak mailprak commented Apr 25, 2026 •

Copy link
Copy Markdown
Contributor

New Features

Added a Kyverno toolset (kyverno/core) exposing comprehensive kubectl-based tools for troubleshooting the Kyverno policy engine, including listing and inspecting ClusterPolicies and namespaced Policies, querying PolicyReport and ClusterPolicyReport summaries and details to surface violation messages and affected resources, inspecting UpdateRequests for generate/mutate-existing rule failures, and streaming admission, background, and reports controller logs with automatic LLM summarization for large log volumes.

The toolset includes guided LLM instructions that enforce a structured investigation order — starting from active policies and failure actions (Enforce vs Audit), narrowing to namespaces with violations via report summaries, then drilling into specific violation messages and resource names — and auto-detects Kyverno's presence via a prerequisite check against the kyverno.io API group.

Documentation

Added comprehensive Kyverno documentation (docs/data-sources/builtin-toolsets/kyverno.md) covering prerequisites, RBAC requirements for kyverno.io and reports.kyverno.io API groups, configuration examples for both Holmes CLI and Robusta Helm Chart deployments, and common use case prompts. Integrated Kyverno into the toolset index page and site navigation.

Tests

Added an LLM evaluation test (tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/) with a complete end-to-end scenario: installs Kyverno if not present, creates a ClusterPolicy in Audit mode that requires a team label on pods, deploys a violating pod (unlabeled-api) without that label, waits for a PolicyReport with failures (with a pod-recreation fallback to force fresh admission evaluation), and verifies that Holmes correctly identifies the policy name, the violating resource, and the embedded verification code HOLMES-EVAL-KYVERNO-001 from the violation message.

Summary by CodeRabbit

  • New Features

    • Added Kyverno integration for troubleshooting policy violations, admission webhook failures, UpdateRequests, and controller logs.
  • Documentation

    • Added Kyverno docs, README/data-sources entry, navigation/index updates, install/config guidance, configuration examples, and sample troubleshooting queries.
  • Tests

    • Added end-to-end Kyverno test fixtures (positive and negative cases) and fixture toolset configurations to validate detection and workflows.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This pull request is from a fork — automated review is disabled. A repository maintainer can comment @claude review to run a one-time review.

@linux-foundation-easycla

linux-foundation-easycla Bot commented Apr 25, 2026 •

Copy link
Copy Markdown

CLA Not Signed

@coderabbitai

coderabbitai Bot commented Apr 25, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 0a8f0eeb-8a8d-48d7-b54c-8e5b9d01684e

📥 Commits

Reviewing files that changed from the base of the PR and between 1272877 and 07a9ba4.

📒 Files selected for processing (2)
  • tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml
  • tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/test_case.yaml
🚧 Files skipped from review as they are similar to previous changes (2)
  • tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/test_case.yaml
  • tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml

Walkthrough

Adds a Kyverno integration: docs (README, nav, index, kyverno.md), a new toolsets.kyverno/core toolset (kubectl-based diagnostic tools and a log summarizer transformer), and LLM test fixtures for positive and negative Kyverno policy-evaluation scenarios.

Changes

Kyverno integration

Layer / File(s) Summary
Docs / Navigation
README.md, docs/data-sources/builtin-toolsets/.nav.yml, docs/data-sources/builtin-toolsets/index.md, docs/data-sources/builtin-toolsets/kyverno.md
Adds Kyverno row to Data Sources table, nav entry, index card, and a new Kyverno guide with install/RBAC/config snippets and example Holmes queries.
Toolset Definition (Core)
holmes/plugins/toolsets/kyverno.yaml
Adds toolsets.kyverno/core definition with prerequisites and multiple kubectl-based tools for listing/getting ClusterPolicy/Policy, PolicyReport/ClusterPolicyReport summaries, UpdateRequests, and Kyverno controller logs; includes an LLM log-summarization transformer.
Tests / Fixtures
tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/*, tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/*
Adds end-to-end LLM fixtures: provisioning namespace and ClusterPolicy, deploying violating Pods, polling PolicyReports with recreate retry logic; enables kyverno/core+kubernetes/core for test 257 and kubernetes/core for test 258.
Docs Update
docs/why-holmesgpt.md
Adds Kyverno to the example Infrastructure read-only integrations list.

Sequence Diagram(s)

sequenceDiagram
    participant User
    participant Holmes
    participant Kubectl as "kubectl / K8s API"
    participant Kyverno as "Kyverno controllers / CRs"
    participant LLM as "Log summarizer (LLM)"
    User->>Holmes: Request Kyverno investigation
    Holmes->>Kubectl: Run toolset commands (list/get policies, reports, updatereqs, logs)
    Kubectl->>Kyverno: Query CRDs and controller logs
    Kyverno-->>Kubectl: Return resources and logs
    Kubectl-->>Holmes: Return command outputs
    Holmes->>LLM: Send logs + transformer prompt
    LLM-->>Holmes: Summarized findings
    Holmes-->>User: Present investigation summary and commands
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • arikalon1
  • moshemorad
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Add kyverno built-in toolset support' clearly and directly describes the main change: adding Kyverno support as a new built-in toolset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 7/8 reviews remaining, refill in 7 minutes and 30 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@netlify

netlify Bot commented Apr 25, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for holmes-docs ready!

Name Link
🔨 Latest commit 07a9ba4
🔍 Latest deploy log https://app.netlify.com/projects/holmes-docs/deploys/69f61acf598d6b0008f841f8
😎 Deploy Preview https://deploy-preview-1950--holmes-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🧹 Nitpick comments (4)
tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml (1)

14-14: include_tool_calls: true may not be needed here.

The expected_output already pins very specific values (policy name, resource name, and the HOLMES-EVAL-KYVERNO-001 verification code), which is sufficient to rule out hallucinations. Including tool calls increases eval runtime and prompt size without adding signal.

As per coding guidelines: "use include_tool_calls: true only when expected output is too generic to rule out hallucinations - prefer specific value checking when possible".

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In
`@tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml`
at line 14, The test fixture currently enables include_tool_calls which isn't
necessary because the expected_output already asserts concrete values (policy
name, resource name, and verification code); update the test case by removing
include_tool_calls or setting include_tool_calls: false in the YAML so tool call
logging is not performed, leaving the expected_output assertions intact (refer
to the include_tool_calls key in the test_ask_holmes fixture).
holmes/plugins/toolsets/kyverno.yaml (3)

57-59: Tool name suggests "get one" but command lists all reports in the namespace.

kyverno_get_policy_report runs kubectl get policyreport -n {{ namespace }} -o yaml which returns every PolicyReport in the namespace, not a specific one. The singular name (paired with the singular kyverno_get_cluster_policy_report which does take a report_name) is likely to confuse the LLM into supplying a report_name template variable that is silently ignored. Either rename to kyverno_list_policy_reports_detailed / kyverno_get_policy_reports, or add an optional report_name parameter so a single report can be fetched.

🛠️ Suggested fix
-      - name: "kyverno_get_policy_report"
-        description: "Get the full PolicyReport for a namespace including all individual rule results with violation messages and affected resource names"
-        command: "kubectl get policyreport -n {{ namespace }} -o yaml 2>&1"
+      - name: "kyverno_get_policy_report"
+        description: "Get full PolicyReport YAML for a namespace. If report_name is provided, fetch that specific report; otherwise return all PolicyReports in the namespace, including individual rule results, violation messages, and affected resource names."
+        command: "kubectl get policyreport{% if report_name %} {{ report_name }}{% endif %} -n {{ namespace }} -o yaml 2>&1"

33-34: Prerequisite check is reasonable; minor robustness suggestion.

kubectl api-resources --api-group=kyverno.io --no-headers | grep -q clusterpolicies correctly auto-detects Kyverno presence. One minor consideration: in clusters where the API server is briefly unavailable, kubectl api-resources can hang or return an empty list; consider adding --request-timeout=5s so the toolset prerequisite never blocks Holmes startup.

🛠️ Suggested fix
-      - command: "kubectl api-resources --api-group=kyverno.io --no-headers 2>/dev/null | grep -q clusterpolicies"
+      - command: "kubectl api-resources --api-group=kyverno.io --no-headers --request-timeout=5s 2>/dev/null | grep -q clusterpolicies"
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@holmes/plugins/toolsets/kyverno.yaml` around lines 33 - 34, The prerequisites
command that auto-detects Kyverno can hang when the API server is slow; update
the command string under the prerequisites key (the existing "kubectl
api-resources --api-group=kyverno.io --no-headers 2>/dev/null | grep -q
clusterpolicies") to include a short request timeout (e.g., add
--request-timeout=5s) while preserving the stderr redirection and grep check so
the prerequisite never blocks Holmes startup.

5-5: Self-host the Kyverno logo instead of hot-linking main.

https://raw.githubusercontent.com/kyverno/kyverno/main/img/logo.png floats with upstream; if Kyverno renames or moves the file the icon will silently 404. Other toolsets in this repo ship their logos under images/integration_logos/. Add a kyverno-icon.png (or pin to a tagged commit/release) and reference it here and from README.md.

Based on learnings: "When adding a new integration (toolset), … add logo to images/integration_logos/".

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@holmes/plugins/toolsets/kyverno.yaml` at line 5, The kyverno toolset
currently hot-links the logo via icon_url pointing to the Kyverno repo main
branch; add a local copy under images/integration_logos (e.g.,
images/integration_logos/kyverno-icon.png) or reference a pinned commit/release
URL, then update the icon_url value in holmes/plugins/toolsets/kyverno.yaml to
point to that local asset (and update any README.md references to use the same
local path), ensuring the symbol to change is the icon_url entry in kyverno.yaml
and the README references to the Kyverno logo.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@README.md`:
- Line 66: README.md currently reuses kubernetes-icon.png for Kyverno; add a new
kyverno-icon.png (PNG) into images/integration_logos/ and update the README.md
line that references kubernetes-icon.png to point to
images/integration_logos/kyverno-icon.png and keep the existing link text to
Kyverno; also open docs/why-holmesgpt.md and add Kyverno to the supported
integrations list (a short mention consistent with other entries) so the docs
reflect the new integration.

In
`@tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml`:
- Around line 52-56: The error message stating "Kyverno failed to become ready
after 120 seconds" is incorrect because the readiness loop uses 60 iterations of
`kubectl wait --timeout=5s` plus `sleep 2`, giving ~7 minutes total; update the
message to reflect the actual timeout (e.g., "after ~7 minutes" or "after 420
seconds") or adjust the loop/iteration count to truly match 120 seconds;
reference the KYVERNO_READY check and the surrounding loop that calls `kubectl
wait --timeout=5s` and `sleep 2` when making the change.
- Around line 25-31: Replace the floating "latest" install with a pinned Kyverno
release (v1.17.1) and make installation idempotent: instead of using the
namespace-only existence check and `kubectl create -f
https://.../latest/.../install.yaml`, verify a Kyverno component/CRD is present
(e.g., check for the kyverno deployment in the kyverno namespace or the
kyvernopolicies CRD) and if absent apply the pinned manifest using an idempotent
method (e.g., `kubectl apply --server-side -f` or `helm upgrade --install`
against the v1.17.1 chart); ensure the code references the pinned URL for
v1.17.1 and swaps `kubectl create -f` for an apply/upgrade path so repeated runs
won’t error when resources already exist.

---

Nitpick comments:
In `@holmes/plugins/toolsets/kyverno.yaml`:
- Around line 33-34: The prerequisites command that auto-detects Kyverno can
hang when the API server is slow; update the command string under the
prerequisites key (the existing "kubectl api-resources --api-group=kyverno.io
--no-headers 2>/dev/null | grep -q clusterpolicies") to include a short request
timeout (e.g., add --request-timeout=5s) while preserving the stderr redirection
and grep check so the prerequisite never blocks Holmes startup.
- Line 5: The kyverno toolset currently hot-links the logo via icon_url pointing
to the Kyverno repo main branch; add a local copy under images/integration_logos
(e.g., images/integration_logos/kyverno-icon.png) or reference a pinned
commit/release URL, then update the icon_url value in
holmes/plugins/toolsets/kyverno.yaml to point to that local asset (and update
any README.md references to use the same local path), ensuring the symbol to
change is the icon_url entry in kyverno.yaml and the README references to the
Kyverno logo.

In
`@tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml`:
- Line 14: The test fixture currently enables include_tool_calls which isn't
necessary because the expected_output already asserts concrete values (policy
name, resource name, and verification code); update the test case by removing
include_tool_calls or setting include_tool_calls: false in the YAML so tool call
logging is not performed, leaving the expected_output assertions intact (refer
to the include_tool_calls key in the test_ask_holmes fixture).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 143b3845-1300-49e4-832e-84ef44442e0d

📥 Commits

Reviewing files that changed from the base of the PR and between 2be63a9 and 82fe7b7.

📒 Files selected for processing (7)
  • README.md
  • docs/data-sources/builtin-toolsets/.nav.yml
  • docs/data-sources/builtin-toolsets/index.md
  • docs/data-sources/builtin-toolsets/kyverno.md
  • holmes/plugins/toolsets/kyverno.yaml
  • tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml
  • tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/toolsets.yaml

Comment thread README.md Outdated
Comment thread tests/llm/fixtures/test_ask_holmes/257_kyverno_policy_violations/test_case.yaml Outdated
naomi-robusta

This comment was marked as off-topic.

@naomi-robusta

Copy link
Copy Markdown
Collaborator

Hi there! Thanks for the pr submission.
Can you please explain why this requires a separate toolset?
It seems like this can be covered by bash / kubectl toolsets.
Thanks!
Naomi

@mailprak

Copy link
Copy Markdown
Contributor Author

Hi there! Thanks for the pr submission. Can you please explain why this requires a separate toolset? It seems like this can be covered by bash / kubectl toolsets. Thanks! Naomi

Hi @naomi-robusta
Thanks for the review! Happy to explain the reasoning.

The generic kubectl/bash toolsets can technically run any kubectl command, but they don't know which commands to run for Kyverno — and that's the core problem this toolset solves.

Kyverno violations require a specific traversal: list active policies and their failure action (Enforce vs Audit) → check PolicyReport summaries by namespace → drill into individual violation messages → inspect UpdateRequests for generate/mutate failures → check controller logs. The llm_instructions block encodes this directly into the LLM's context so Holmes follows the right path every time, rather than exploring ad hoc.

  • kubectl-backed tools with domain-specific instructions and prerequisites — rather than relying on the generic toolset.
  • Kyverno has achieved CNCF Graduation as of March 2026, solidifying its role as a premier policy-as-code solution with over 3 billion downloads

@naomi-robusta

Copy link
Copy Markdown
Collaborator

@mailprak
I believe that it can be achieved by adding a skill. Can you try that option first?
Also, can you create an eval that shows that Holmes wasn't able to figure it out on its own?

@mailprak

mailprak commented May 2, 2026

Copy link
Copy Markdown
Contributor Author

@mailprak I believe that it can be achieved by adding a skill. Can you try that option first? Also, can you create an eval that shows that Holmes wasn't able to figure it out on its own?

@naomi-robusta Sure,
Created an additional eval. Please review.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In
`@tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/test_case.yaml`:
- Around line 7-8: Update the expected evaluation strings to use the actual
ClusterPolicy resource name instead of the rule name: replace occurrences like
"Must mention the policy name 'require-team-label'" with the full resource
identifier "ClusterPolicy/require-team-label-258" (and similarly update the
related expectations at the other referenced locations). Locate and edit the
fixture expectations in
test_ask_holmes/258_kyverno_without_toolset/test_case.yaml that reference
'require-team-label' (including the blocks around lines 24-25 and 68-73) so they
assert the exact policy identifier and the exact violating resource name
'unlabeled-api'.
- Around line 39-60: The script currently only waits for
deployment/kyverno-admission-controller, but PolicyReport creation also requires
the reports controller (and ideally the background controller) to be ready;
update the readiness loop to check all three
deployments—kyverno-admission-controller, kyverno-reports-controller, and
kyverno-background-controller—before setting KYVERNO_READY to true (e.g., test
each deployment with kubectl wait and only break when all three succeed), and
keep the existing timeout/failure behavior and diagnostic kubectl get pods call
if readiness fails.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 053aff4d-7747-411a-a9df-4c12864ecfb3

📥 Commits

Reviewing files that changed from the base of the PR and between 6ebcd60 and 1272877.

⛔ Files ignored due to path filters (1)
  • images/integration_logos/kyverno-icon.png is excluded by !**/*.png
📒 Files selected for processing (2)
  • tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/test_case.yaml
  • tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/toolsets.yaml
✅ Files skipped from review due to trivial changes (1)
  • tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/toolsets.yaml

Comment thread tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/test_case.yaml Outdated
Comment thread tests/llm/fixtures/test_ask_holmes/258_kyverno_without_toolset/test_case.yaml Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants