The Compliance Gap at Banking Scale

▶ Watch (1:33)

Chase UK launched in September 2021 and crossed 2.5 million customers and 20 billion pounds in deposits within five years. Behind that sits thousands of nodes across roughly 15 clusters. The first question in that environment is never networking or scalability. It is whether the platform will pass an audit. The team had a compliance process, not a compliance system: quarterly spreadsheets, ad-hoc kubectl commands, and inconsistent reports generated whenever someone asked. All of it was manual.

Why OPA Gatekeeper Did Not Scale

▶ Watch (5:28)

OPA Gatekeeper was already deployed when Chase UK went live. After three to four years of development, it had produced four policies in production. Rego expertise was thin in 2022 and 2023. The engineers who built the original policies had left, taking domain knowledge with them. No reporting meant no ownership: when something broke, no one knew who was responsible for the resource. The team evaluated building in-house tooling, other policy engines, and Kyverno before picking Kyverno.

Kyverno: Five Policy Types and Built-In Reporting

▶ Watch (7:42)

Kyverno ships five policy types: validate, mutate, generate, delete, and image verification. Validate enforces configuration baselines. Mutate changes resources in cluster on admission, which matters because attackers skip pipelines and land directly in cluster. Generate creates roles, role bindings, and network policies automatically when a new namespace appears. Delete cleans up orphaned or TTL-expired resources. Reporting ships as a separate Open Reports project that produces standardized output consumable by developers, operators, and security teams through a single API.

The Chase UK Stack: Kyverno, Prometheus, Thanos, Grafana

▶ Watch (17:22)

Kyverno sits as an admission controller in every cluster at Chase UK. It is part of the base cluster definition, present from the moment a cluster is built. Kyverno policy results feed into Prometheus, aggregate through Thanos, and surface in one Grafana dashboard. That dashboard lets a security engineer filter by pod security standards category, a team lead filter by namespace, and a platform engineer filter by a single policy to see the current failure rate before rolling enforcement. Kyverno admission latency across the full estate stays below 20 milliseconds, well under the 100-millisecond threshold where queuing starts affecting workloads.

From Four Policies to 46: Results and Hard Lessons

▶ Watch (22:34)

The migration from OPA Gatekeeper to Kyverno took one month in a bank, including decommissioning the old tool and moving all four policies to production. By 2024 to 2026, the policy count grew to 46. The 2023 results: 7 to 8 months of engineering effort saved, 25 percent more automation, and cleaner Kubernetes upgrade cycles because a policy showed exactly which applications used deprecated APIs. The auditors signed off. Two lessons stood out: always test policies in CI because one bad policy can affect an entire cluster, and start in enforce mode rather than audit mode whenever possible. Staying in audit mode delays enforcement indefinitely.

Notable Quotes

will this pass an audit? That’s the first thing what we think about, right? Nischay Goyal · ▶ 01:28

we didn’t have a compliance system, we actually had a compliance process. Nischay Goyal · ▶ 03:02

attackers don’t go through your pipeline, they are in cluster already. Jim Bugwadia · ▶ 11:38

fixing a problem takes less time compared to gathering all the information to fix the problem. Nischay Goyal · ▶ 21:30

our auditors were happy. And I think that was one of the hardest SLA or the KPI to meet. Nischay Goyal · ▶ 25:44

Key Takeaways

  • Chase UK grew from 4 OPA policies to 46 Kyverno policies in under three years.
  • One Grafana dashboard, filtered by cluster, namespace, or policy, replaced manual quarterly spreadsheets for auditors.
  • Start policies in enforce mode from day one; staying in audit mode delays compliance indefinitely.

About the Speaker(s)

Nischay Goyal is a Platform Compliance Lead (SVP) at JP Morgan Chase, focused on building audit-ready Kubernetes platforms in highly regulated environments, with deep expertise in EKS and embedding governance directly into platform tooling.

Jim Bugwadia is co-founder and CEO of Nirmata, the Kubernetes policy and governance company. He serves as co-chair of the Kubernetes Policy and Multi-Tenancy Working Groups and is a co-creator and maintainer of the Kyverno project.