Beyond Security: Leveraging OPA for FinOps in Kubernetes - Sathish Kumar Venkatesan
Sathish Kumar Venkatesan
KubeCon + CloudNativeCon Europe 2025 · Session
Overview
In the dynamic landscape of cloud-native environments, managing costs effectively has become as critical as ensuring robust security. This talk, "Beyond Security: Leveraging OPA for FinOps in Kubernetes," delivered by Sathish Kumar Venkatesan at KubeCon EU, explores a paradigm shift: utilizing the Open Policy Agent (OPA), a tool traditionally associated with security and compliance, to implement robust FinOps practices within Kubernetes clusters. Venkatesan argues that by extending OPA's capabilities, organizations can proactively govern cloud spend, optimize resource utilization, and foster a culture of cost accountability.

Key moments
- 0:00 Introduction and talk agenda overview
- 2:00 Kubernetes FinOps challenges and resource waste statistics
- 3:15 Introduction to OPA: A CNCF graduated policy engine
- 5:00 Why OPA is ideal for FinOps governance
- 6:00 OPA Gatekeeper: Kubernetes admission controller integration
- 8:00 Applying OPA to FinOps: Tagging and compute optimization
Beyond Security: Leveraging OPA for FinOps in Kubernetes
Speakers: Sathish Kumar Venkatesan
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=aiC7C56pE7I
Overview
In the dynamic landscape of cloud-native environments, managing costs effectively has become as critical as ensuring robust security. This talk, "Beyond Security: Leveraging OPA for FinOps in Kubernetes," delivered by Sathish Kumar Venkatesan at KubeCon EU, explores a paradigm shift: utilizing the Open Policy Agent (OPA), a tool traditionally associated with security and compliance, to implement robust FinOps practices within Kubernetes clusters. Venkatesan argues that by extending OPA's capabilities, organizations can proactively govern cloud spend, optimize resource utilization, and foster a culture of cost accountability.
The presentation addresses the persistent challenge of cloud waste in Kubernetes, citing alarming statistics on underutilized resources and overprovisioning. It then introduces OPA as a powerful, flexible policy engine capable of providing the necessary guardrails. The core proposition is that OPA, particularly its Kubernetes integration via Gatekeeper, can enforce cost-saving policies at the point of resource provisioning, adopting a "shift-left" approach to FinOps. This not only reduces reactive cost remediation but also integrates financial accountability directly into the development and deployment pipeline.
This article delves into Venkatesan's arguments, technical demonstrations, and practical recommendations for integrating OPA into an organization's FinOps strategy. It highlights how the same policy framework used for security can be repurposed to tackle economic inefficiencies, offering a unified approach to governance in complex cloud environments. By the end, readers will understand the compelling case for OPA as a versatile tool for FinOps, enabling organizations to gain greater visibility and control over their Kubernetes cloud expenditure.
Background
▶ Watch: Introduction and talk agenda overview (0:00)
The proliferation of Kubernetes has revolutionized application deployment and scaling, but it has also introduced significant challenges in managing cloud costs. As Venkatesan highlights, organizations frequently grapple with substantial waste due to underutilized and overprovisioned resources. A Flexera state report indicates that 32% of resources are underutilized, while a Kasten report specifically on Kubernetes clusters found that only 10% of CPU and 23% of memory are typically utilized, implying that over 50% of memory is often paid for but unused.
Several common issues contribute to this problem:
- Overprovisioned Resources: Workloads are often allocated more CPU and memory than they actually consume, leading to unnecessary expenditure.
- Idle Workloads: Resources remain allocated for applications that are not actively running or are infrequently used.
- Non-optimal Node Selection: Developers or platform teams may provision clusters with inappropriate or oversized virtual machine instances, resulting in inefficient resource packing.
- Lack of Resource Quotas: Without strict resource requests and limits defined, workloads can consume arbitrary amounts of underlying hardware, making cost prediction and control difficult.
- Untagged Resources: A significant hurdle for chargeback and cost allocation in multi-tenant environments is the absence of consistent tagging, making it impossible to attribute costs to specific teams or business units.
To combat these challenges, organizations adopt FinOps, a cultural practice that brings financial accountability to the variable spend model of cloud. Its core goals include visibility into cloud bills, effective cost optimization (e.g., right-sizing, reservations), and continuous operation to identify and remediate overspend. However, implementing FinOps guardrails in the dynamic, declarative nature of Kubernetes requires a robust policy enforcement mechanism.
This is where Open Policy Agent (OPA) steps in. OPA is a Cloud Native Computing Foundation (CNCF) graduated project (since 2021) that serves as a general-purpose policy engine. It allows users to define policies for various systems, including Kubernetes, Terraform, and APIs, using a high-level declarative language called Rego. A key benefit of OPA is its ability to decouple policy logic from application logic, centralizing decision-making and allowing policies to be version-controlled like code. While widely adopted for security controls, compliance checks, and API authorization, Venkatesan's talk makes a compelling case for extending OPA's reach into the realm of FinOps.
Key Findings
▶ Watch: Introduction to OPA: A CNCF graduated policy engine (3:15)
Sathish Kumar Venkatesan's talk underscores several key findings regarding the application of OPA for FinOps in Kubernetes:
- OPA's Versatility Beyond Security: The fundamental finding is that OPA, primarily known for security and compliance enforcement (e.g., image policies, network policies, privileged container restrictions), is equally capable and effective in addressing FinOps challenges. This allows organizations to leverage an existing, familiar tool for a new, critical purpose.
- Shift-Left FinOps: By integrating OPA, particularly via Gatekeeper as an admission controller in Kubernetes, organizations can implement a "shift-left" approach to FinOps. Instead of identifying and remediating overspend after resources are provisioned, OPA policies can deny the creation of non-compliant or excessively costly resources before they are deployed. This proactive approach prevents waste at its source.
- Unified Policy Framework: OPA provides a single, centralized policy framework that can span multiple domains—security, compliance, and FinOps. This reduces tool sprawl and simplifies policy management, as policies written in Rego can be version-controlled and deployed using GitOps methodologies.
- Tangible Cost Savings through Enforcement: The talk demonstrates that OPA can enforce concrete policies to reduce cloud spend, such as mandating resource requests and limits, enforcing the use of cheaper spot instances for non-production workloads, dictating storage class usage based on environment, and ensuring proper tagging for chargeback. These policies translate directly into optimized resource utilization and clearer cost attribution.
- Integration with External Cost Tools: OPA's flexibility allows it to integrate with external cost monitoring tools like OpenCost. This enables dynamic, real-time cost governance, where OPA policies can make decisions based on current spending metrics or projected costs, denying deployments that would exceed predefined budgets.
These findings collectively demonstrate that OPA offers a powerful and practical solution for embedding financial governance directly into the Kubernetes operational workflow, transforming reactive cost management into a proactive and automated process.
Technical Deep Dive
▶ Watch: Why OPA is ideal for FinOps governance (5:00)
The technical core of leveraging OPA for FinOps in Kubernetes revolves around the Rego policy language and its integration with Kubernetes via OPA Gatekeeper. OPA functions as a policy engine that receives input (e.g., a Kubernetes admission request), evaluates it against a set of policies written in Rego, and produces a decision (e.g., allow or deny).
Rego Fundamentals:
Rego is a declarative language designed for expressing policies. A basic Rego policy might look like this (as shown in the talk for an API access example):
This policy allows a GET request to the /users endpoint only if the user is alice. For FinOps, Rego policies inspect Kubernetes resource manifests (Pods, Deployments, PVCs, Namespaces) and evaluate conditions related to resource requests, limits, labels, annotations, and storage classes.
OPA Gatekeeper for Kubernetes:
Gatekeeper is a Kubernetes admission controller that integrates OPA directly into the Kubernetes API server. When a user attempts to create, update, or delete a resource, the API server sends the admission request to Gatekeeper. Gatekeeper then evaluates the request against OPA policies (known as constraints in Gatekeeper terminology) and either allows or denies the operation.
Gatekeeper provides:
- Admission Control: Enforces policies on incoming requests, preventing non-compliant resources from being created.
- Auditing Capabilities: Can scan existing resources in the cluster for policy violations, providing insights into pre-existing issues that might lead to overspend.
- Constraint Templates: Define the schema and Rego logic for different types of policies, making them reusable and manageable. Users then create
Constraintcustom resources (CRs) that instantiate these templates with specific parameters (e.g., a specific CPU limit).
FinOps Policy Examples in Rego:
Venkatesan presented several concrete examples of FinOps policies:
- Compute Optimization (Resource Requests/Limits):
A policy can deny deployments that exceed specific CPU or memory thresholds. For instance, to prevent excessive CPU allocation:
This policy could be configured via a K8sPsPContainerLimits or similar ConstraintTemplate to enforce maximum CPU limits (e.g., 1000 millicores or 1 CPU) or minimum requests (e.g., 100 millicores) to ensure resources are right-sized and not overprovisioned.
- Spot Instance Enforcement:
For non-production environments, policies can mandate the use of cheaper spot instances by requiring specific labels on deployments or namespaces.
This ensures that cost-saving options like spot instances (70-80% cheaper) are utilized where appropriate.
- Cost Allocation (Tagging Enforcement):
Critical for chargeback, policies can mandate specific labels (e.g., cost-center, environment) on namespaces or deployments.
This enables accurate cost tracking and accountability across different teams.
- Storage Cost Optimization:
Policies can restrict the use of expensive storage classes (e.g., Premium SSDs) to only critical or production environments.
Enforcement Actions and Mutation:
Gatekeeper allows various enforcement actions:
deny: Prevents the resource from being created or updated.warn: Allows the resource but logs a warning about the violation.dry run(oraudit): Only checks for violations without taking action, useful for testing and auditing existing resources.
Venkatesan also briefly mentioned OPA's mutation capabilities. While Gatekeeper primarily focuses on validation, OPA can be used in a mutating admission webhook to automatically modify resources (e.g., adding missing labels or setting default resource requests/limits if they are too low). This moves beyond just denial to automated remediation, though it adds complexity.
Challenges and Best Practices:
Implementing OPA for FinOps involves its own set of challenges:
- Rego Testing: Writing robust Rego policies requires good test cases. Tools like
opa testandConftestare essential for validating policy logic. - Dry Run First: Always start with
dry runorwarnmodes to understand the impact of policies before enforcingdenyto avoid disrupting legitimate workloads. - Exception Handling: Provide mechanisms for exceptions, perhaps using specific annotations that temporarily bypass certain policies for critical, non-compliant workloads.
- Dynamic Cloud Bills: Cloud costs are constantly changing. Policies that rely on cost data need real-time integration with external billing APIs or cost management tools to remain accurate.
- GitOps for Policies: Manage policies in a Git repository and use GitOps tools (e.g., Flux CD, Argo CD) to ensure policies are version-controlled, reviewed, and consistently applied across clusters.
Overall, the technical deep dive reveals OPA's flexibility and power in becoming a central component of an automated FinOps strategy within Kubernetes, enabling granular control over cloud resource consumption.
Demo / Proof of Concept
▶ Watch: OPA Gatekeeper: Kubernetes admission controller integration (6:00)
Sathish Kumar Venkatesan provided a compelling live demonstration of OPA Gatekeeper enforcing FinOps policies in a Kubernetes cluster. The setup included OPA Gatekeeper and OpenCost, an open-source cost monitoring tool for Kubernetes, highlighting a practical integration for real-time cost governance.
The demonstration showcased three primary scenarios:
- Storage Class Restriction:
- Policy: A policy was in place to restrict the use of the
premium-ssdstorage class exclusively to theprodnamespace, denying its use in other environments likedev. - Action: Venkatesan attempted to create a
PersistentVolumeClaim (PVC)requestingpremium-ssdin thedevnamespace. - Outcome: Gatekeeper immediately denied the request, preventing the creation of the PVC. The error message clearly indicated that
premium-ssdwas not allowed in thedevnamespace. - Verification: He then successfully created the same PVC in the
prodnamespace, demonstrating the policy's conditional enforcement. This validates the ability to optimize storage costs by ensuring expensive storage types are only used where absolutely necessary.
- Mandatory Resource Requests/Limits:
- Policy: Another policy required all deployments to specify CPU and memory requests and limits.
- Action: A deployment manifest was applied that intentionally omitted these resource specifications.
- Outcome: Gatekeeper denied the deployment, stating "missing CPU request which is required." This reinforces the crucial practice of defining resource requirements, which is fundamental for efficient scheduling and cost allocation.
- Dynamic Budget Enforcement with OpenCost Integration:
- Policy: This was the most advanced scenario, demonstrating integration with OpenCost. Two policies were active: one enforcing minimum/maximum CPU requests/limits (e.g., min 100 millicores, max 1000 millicores), and a second policy that predicted the cost impact of a new deployment against a predefined namespace budget of $5,000.
- Mechanism: Venkatesan explained that he had a custom application pulling data from the OpenCost API to calculate current spend and project future costs based on new deployments. For the demo, the current spend for the
defaultnamespace was around $4,500. - Action 1 (Denied): He attempted to deploy a workload requesting 3 CPU cores. This deployment was projected to add approximately $2,700 to the monthly spend, pushing the total to $7,200, exceeding the $5,000 budget.
- Outcome 1: Gatekeeper denied the deployment, effectively preventing the budget overrun.
- Action 2 (Allowed): Next, he applied a deployment requesting only 100 millicores. This workload's cost was minimal and kept the total projected spend well within the $5,000 budget.
- Outcome 2: The deployment was successfully created.
- Auditing: Venkatesan also showed how Gatekeeper's auditing capabilities could reveal violations for existing resources, such as namespaces missing required
cost-centerorenvironmentlabels, or existing workloads that would exceed a monthly budget if they continued running.
The demo clearly illustrated OPA's power as a Kubernetes admission controller for FinOps. It moved beyond theoretical concepts to concrete examples of how policies written in Rego can proactively prevent cost overruns, enforce best practices for resource allocation, and integrate with real-time cost data to make intelligent, automated decisions at the point of deployment.
Defensive Implications
▶ Watch: Applying OPA to FinOps: Tagging and compute optimization (8:00)
Leveraging OPA for FinOps provides significant defensive advantages against uncontrolled cloud spending and operational inefficiencies in Kubernetes environments. These implications extend beyond mere cost reduction to foster a more resilient, accountable, and optimized cloud infrastructure.
- Proactive Cost Control (Shift-Left FinOps): The primary defensive implication is the ability to implement a "shift-left" strategy for FinOps. By enforcing policies at the admission control layer via OPA Gatekeeper, organizations can prevent costly misconfigurations or overprovisioning before resources are deployed. This moves from reactive cleanup of cloud waste to proactive prevention, significantly reducing the financial blast radius of errors.
- Enhanced Resource Optimization: Defenders can mandate specific resource requests and limits for all workloads, ensuring that applications are appropriately sized. This defends against both egregious overprovisioning (paying for unused capacity) and under-provisioning (which can lead to performance issues and subsequent over-scaling in an attempt to compensate). Policies can also enforce the use of cost-effective instance types (e.g., spot instances for non-production) or deny inefficient node selections.
- Improved Chargeback and Accountability: By enforcing mandatory tagging (e.g.,
cost-center,environment,project) on namespaces, deployments, and other resources, organizations gain the ability to accurately attribute costs to specific teams, departments, or projects. This defends against the "unaccounted spend" problem in multi-tenant clusters, fostering greater financial accountability across the organization. - Standardization and Compliance for Cost: OPA allows for the standardization of resource configurations and operational practices that impact cost. For instance, policies can dictate which storage classes are permitted in certain environments or ensure that all workloads adhere to a baseline of efficiency. This brings a compliance-like rigor to cost management, ensuring consistency and predictability.
- Reduced Cloud Waste and Carbon Footprint: By actively preventing the deployment of overprovisioned or idle resources, organizations directly reduce cloud waste. This not only saves money but also contributes to a lower carbon footprint, aligning with broader sustainability goals.
- Leveraging Existing Security Investments: One of the most powerful defensive implications is the ability to repurpose an existing security tool (OPA) for financial governance. This avoids the overhead of introducing new tools, reduces the learning curve for teams already familiar with OPA/Rego, and consolidates policy enforcement under a single, well-understood framework.
- Early Detection of Cost Anomalies: Integrating OPA with external cost monitoring tools like OpenCost enables real-time budget enforcement. This acts as an early warning system, preventing deployments that would push costs beyond predefined thresholds, thus defending against unexpected spikes in cloud bills.
- Automated Remediation Potential: While primarily a validation engine, OPA's mutation capabilities hint at a future where FinOps policies could not only deny but also automatically correct certain misconfigurations (e.g., adding missing resource requests) to bring workloads into compliance, further strengthening defensive posture against cost inefficiencies.
In essence, OPA transforms FinOps from a manual, reactive process into an automated, integrated defense mechanism against cloud cost overruns, poor resource hygiene, and lack of financial accountability within Kubernetes environments.
Key Takeaways
- OPA is a versatile policy engine: Beyond its traditional role in security and compliance, Open Policy Agent (OPA) can be effectively extended to implement robust FinOps practices in Kubernetes, leveraging a single policy framework for multiple governance domains.
- Shift-Left FinOps prevents waste: By using OPA Gatekeeper as an admission controller, organizations can enforce cost-saving policies at the point of resource provisioning, proactively denying overprovisioned, untagged, or non-compliant resources and preventing cloud waste before it occurs.
- Rego policies enable granular control: The declarative Rego language allows for precise definition of policies to mandate resource requests and limits, enforce cheaper instance types (e.g., spot instances for non-prod), restrict expensive storage classes, and ensure proper tagging for chargeback.
- Dynamic budget enforcement with external tools: OPA can integrate with cost monitoring solutions like OpenCost to enable real-time, dynamic budget enforcement, denying deployments that would exceed predefined cost thresholds based on current and projected spend.
- Collaboration is crucial for success: Effective FinOps implementation with OPA requires strong collaboration between platform, security, finance, and application teams to define, implement, and manage policies, including handling exceptions and ensuring user understanding.
- Start small, test thoroughly, and embrace GitOps: To successfully adopt OPA for FinOps, begin with small, impactful policies, thoroughly test them using
dry runorwarnmodes, and manage policies using GitOps for version control, automated deployment, and consistency across environments.
About the Speaker(s)
Sathish Kumar Venkatesan is a passionate technologist based in Canada, deeply involved in the cloud-native and open-source communities. He is the founder of DevOps Cloud Junction, a community website dedicated to discussing cloud-native technologies, AI, and other emerging tech trends. Venkatesan actively contributes to multiple open-source projects and frequently participates in community events such as KubeCon, demonstrating his commitment to knowledge sharing and collaborative development. His interests span computers, electronics, and photography, reflecting a diverse technical and creative background. (Speaker's title and company were not specified in the provided metadata or transcript).
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Venkatesan delivers a highly practical and technically sound presentation on extending Open Policy Agent (OPA) beyond traditional security use cases to implement robust FinOps practices in Kubernetes. By leveraging OPA Gatekeeper as an admission controller, organizations can proactively enforce cost-saving policies, prevent overprovisioning, and integrate with real-time cost data for dynamic budget enforcement. This isn't just theory; it's a clear roadmap with concrete Rego examples and a compelling demo, offering significant actionable insights for anyone wrestling with Kubernetes cloud spend.
Heather Calloway (CISO) — STRONG ACCEPT
Sathish Kumar Venkatesan's KubeCon talk on leveraging OPA for FinOps in Kubernetes presents a compelling and actionable strategy for tackling cloud waste through proactive policy enforcement. By extending OPA's capabilities beyond traditional security to financial governance, the presentation demonstrates a "shift-left" approach to cost control, mandating resource optimization, enforcing tagging for accountability, and integrating with real-time cost data. This approach offers significant business impact by preventing overspend at the source and provides a unified framework for managing critical enterprise risks in dynamic cloud environments.