The Republic has grown, and so has the chaos. Policies meant for one province are bleeding into another, exceptions have been written too broadly, and a workload that should never have been admitted is slipping through the gates. Policy Reporter shows violations where there should be none, and silence where there should be enforcement.
Your mission: investigate the estate, fix the scoping, and restore order.
Play This Challenge to Learn
- How to scope policies using
ValidatingPolicy(cluster-wide) andNamespacedValidatingPolicy(per-namespace), and when to use each - How CEL expressions in
ValidatingPolicyandPolicyExceptionexpress fine-grained admission conditions - How to write and scope a
PolicyExceptioncorrectly so only the intended workloads are exempt - How to use Policy Reporter and the OpenReports format to audit and debug a policy estate across multiple namespaces
Awards & Deadline
Complete all levels and post your solution in the community before the deadline to be eligible.
1st place: 50% voucher for a Linux Foundation certification
Top 3: Credly badge to showcase the achievement
Deadline: 23 June 2026 at 23:59 CET
Play Now
Share your solutions, your questions, and the moment it clicked in this thread. Weβre looking forward to seeing how you restored order to the Republic.

