Closing the Governance Gap in Nutanix Kubernetes Platform Environments

24 August 2026

Closing the Governance Gap in Nutanix Kubernetes Platform Environments

Nirmata and Nutanix partnership

Every enterprise rolling out Kubernetes at scale eventually hits the same wall: clusters multiply faster than the guardrails around them. A platform team stands up an NKP cluster to give the business a consistent way to run Kubernetes across data center, edge, and cloud but “consistent infrastructure” doesn’t automatically mean “consistent governance.” Two clusters built from the same template can drift into very different security postures within months, and nobody notices until an audit or an incident forces the question.

We’re announcing that Nirmata Enterprise for Kyverno (N4K) is now certified to run on Nutanix Kubernetes Platform (NKP) on the Nutanix Cloud Platform (NCP), so that governance can be integrated within the platform. To learn more about our approach, read our Shift-Down Security blog post.

Why This Gap Keeps Showing Up

The pattern is familiar to anyone who’s scaled Kubernetes past a handful of clusters. Security wants proof that nothing insecure ever reaches a running workload. 

  • Platform engineering wants one set of guardrails it can apply everywhere, not a patchwork of scripts and cluster-specific exceptions. 
  • Compliance wants evidence on demand, not a scramble to reconstruct what was true three months ago. 
  • And developers want all of this to happen without becoming a gate they have to push their way through.

Most organizations solve pieces of this with point tools bolted on after the fact, a scanner here, a manual checklist there. That approach doesn’t scale with the cluster count, and it rarely survives contact with a real audit.

Governance as Part of the Platform, Not Beside It

Nutanix Cloud Platform already gives teams a single, consistent way to provision and operate Kubernetes clusters via NKP. Adding N4K through the Partner Catalog extends that same consistency to policy: it installs and upgrades the way any other catalog application does, so governance is provisioned with the cluster rather than layered on afterward. There’s no separate pipeline to build, no bespoke process per team policy enforcement becomes a property of the platform itself.

Why the Kyverno Model Is the Right One

The reason Kyverno-based governance works where other approaches stall is simple: policies are written as Kubernetes resources, using the same objects and workflows teams already know. There’s no proprietary policy language to learn and no separate control plane to operate. That lowers the barrier for platform and security teams to actually adopt policy-as-code, instead of treating it as a specialist’s tool.

N4K builds enterprise capabilities on top of that open-source foundation multi-cluster management, policy lifecycle controls, exception workflows, role-based access, audit-ready reporting, and highly available, stateless configuration to ensure governance never becomes a single point of failure — backed by Nirmata’s support and enterprise agreement.

What N4K Actually Changes

N4K (Nirmata Enterprise for Kyverno) is Nirmata’s enterprise distribution of Kyverno, the CNCF-graduated policy engine Nirmata created. Additionally, NKP, it gives organizations:

  • Admission-time enforcement, so non-compliant workloads never make it into a running cluster.
  • Fleet-wide policy management from a single control point, instead of per-cluster configuration.
  • Continuous compliance monitoring, mapped to the standards the organization actually has to answer to.
  • Policy delivered as code through existing GitOps workflows, not a separate change process.
  • Reporting that’s generated automatically, rather than assembled by hand before an audit.
  • Seamless interoperability with NKP’s default Cilium CNI, ensuring policy enforcement does not disrupt advanced network microsegmentation.
  • Backed by expert support and reliability from the Nirmata team, designed specifically for enterprise environments.

What Each Team Gets Out of It

Platform teams

Get a single governance standard they can apply across every NKP cluster, without slowing down the developer teams building on top of it.

Security teams

Get visibility into workload compliance as it happens, not after the fact, which cuts down on the slow drift that turns “compliant at launch” into “non-compliant six months later.”

Compliance teams

Get evidence generated continuously instead of reconstructed under deadline pressure — audits stop being a fire drill.

Development teams

Get feedback earlier, when a fix is a small diff instead of a production incident.

The Bigger Picture

Pairing NKP’s operational consistency with Nirmata’s enterprise-ready policy engine means governance scales at the same rate as the cluster fleet, not slower. Organizations get fewer configuration surprises, faster audit cycles, and a platform team that can hold the line on standards without becoming a bottleneck. As more of the business runs on Kubernetes, that’s the difference between governance that actually holds and governance that exists only on paper.

Learn More

  • Find Kyverno in the NKP Partner Catalog under the Security category.
  • Contact sales@nirmata.com for enterprise licensing and support.
  • Learn more about Kyverno at kyverno.io.

For more information, contact us at hello@nirmata.com.

— The Nirmata Team

Beyond the Merge: Enforcing Policy Before the Terraform Apply
Introducing the Remediator Agent: Turning Kyverno Policy Violations into Pull Requests, Automatically.

Latest

From the blog

The latest industry news, interviews, technologies, and resources.

View all blogs
Beyond the Merge: Enforcing Policy Before the Terraform Apply
Beyond the Merge: Enforcing Policy Before the Terraform Apply

Closing the Governance Gap in Nutanix Kubernetes Platform Environments

Introducing OttoFlow: AI Workflows for Kubernetes
Introducing OttoFlow: AI Workflows for Kubernetes

Introducing Nirmata Runtime for Kyverno: Kernel-Level Enforcement for AI Workloads