nvrules2re is a CLI tool that converts NeuVector Process Profile Rules into Kubewarden Runtime Enforcer.
This tool simplifies the migration from NeuVector's Process Profile rules to Kubewarden Runtime Enforcer — a universal policy engine for Kubernetes that streamlines the adoption of policy-as-code practices.
- Parse NeuVector process profile rules (exported via
/v1/file/groupAPI) - Generate equivalent Runtime Enforcer
WorkloadPolicyresources with NV group name as its resource name - Supports output to stdout or to a file
- Optionally enable monitor/protect mode
- Display a summary showing the status of each rule conversion
- Kubernetes cluster connection: Runtime Enforcer is capable of specifying different rules for different container, but it requires the target container name in the WorkloadPolicy. This information is not included in NV process profile rules. You'd require a kubernetes cluster connection in order for
nvrules2reto retrieve the container name for you. - Supported platforms: Linux, macOS, Windows
If you're building from source, you'll need:
- Go: See go.mod for the specific version requirement.
- Make: For building using the provided Makefile
This guide provides step-by-step instructions to set up and execute nvrules2re, help you convert NeuVector Process Profile Rules into Runtime Enforcer WorkloadPolicies within your environment.
You can either:
- Download the latest release binary from the Releases page, or
- Build from source:
makeYou will get rules.yaml
curl "https://<API_SERVER_ADDRESS>/v1/file/group" \
-H "Content-Type: application/json" \
-H "X-Auth-Apikey: <API_KEY>" \
--data-raw '{"groups":["<group name>"]}' \
-o rules.yaml.gz
gunzip rules.yaml.gz- Navigate to Policy → Groups
- Select the group policy that you want to export
- Click Export Group Policy
- Ignore the Process Policy mode. You will be given the option to override it in the
nvrules2relater. - Leave
Use Name Referralunchecked, selectDownload to Localand clickSubmit - You will download a file like
cfgGroupsExport_20260626105448.yamlthat you can use later.
NOTE: You will need kubernetes cluster access in order to run the CLI.
nvrules2re convert <yaml_file>Examples:
# Convert rules from a YAML file (output defaults to stdout)
nvrules2re convert rules.yaml
# Specify custom output file
nvrules2re convert rules.yaml --output my-policies.yaml
# Override all rules to monitor mode
nvrules2re convert rules.yaml --mode monitorTo assign Runtime Enforcer WorkloadPolicy to a workload, you have to add a label in your workload.
NOTE: WorkloadPolicy is namespace-scoped. You'd need to match the WorkloadPolicy's namespace with your workload.
apiVersion: apps/v1
kind: Deployment
metadata:
name: ubuntu-deployment
labels:
app: ubuntu
spec:
replicas: 1
selector:
matchLabels:
app: ubuntu
template:
metadata:
labels:
app: ubuntu
runtimeenforcer.kubewarden.io/policy: workloadpolicy-sample # replace with the WorkloadPolicy name.
spec:
containers:
- name: ubuntu
image: ubuntuInstead of relying on the mode defined in NV process rules, the effective enforcement mode in Runtime Enforcer WorkloadPolicy will always be the one specified by nvrules2re. This is because Runtime Enforcer uses a different kernel hook. We recommend running in monitor mode first before converting it to protect mode to prevent false positives and service interruption.
NAME:
nvrules2re - Convert NeuVector Process Profile rules to Runtime Enforcer WorkloadPolicy
USAGE:
nvrules2re [global options] [command [command options]]
COMMANDS:
convert Convert NvSecurityRule YAML files to WorkloadPolicy YAML
help, h Shows a list of commands or help for one command
GLOBAL OPTIONS:
--help, -h show help
- Avoid double enforcement. After converting NeuVector process rules to Runtime Enforcer WorkloadPolicy, disable the matching NeuVector rules.