Skip to main content
📬 Get weekly Production AI insights Practical notes on Kubernetes, AI infrastructure and platform engineering. No spam. Subscribe free
Policy-Driven Cost Optimisation with Kyverno and VPA title slide at the Platform Engineering Amsterdam meetup, February 2025
Platform Engineering

Platform Engineering Amsterdam Meetup, February 2025

Platform Engineering Amsterdam, February 2025: Kyverno and VPA for cost optimisation, building a platform team, and a talk from free kicks to git commits.

LB
Luca Berton
¡ 4 min read

On the evening of Wednesday 12 February 2025 I went to the Platform Engineering Amsterdam meetup. The opening screen read “Hosted by: mogenius, tarmac”, and both sponsors had banners either side of the stage. mogenius had “Empower your developers with Kubernetes self-service”, and tarmac had “The sky is the limit & the cloud is the playground”. There were tarmac flyers on the tables, describing the company as a “premier nearshore software development partner”.

The room was a cosy pub, with beer signs on the walls, round wooden tables and a small stage with a mic stand. There were three talks, all very different: a hands-on policy talk, a talk on how to organise a platform team, and a personal career story that ended on self-service.

Platform Engineering Amsterdam opening screen hosted by mogenius and tarmac, next to the tarmac banner

The opening screen before the talks: “Platform Engineering Amsterdam, hosted by mogenius and tarmac”.

Policy-Driven Cost Optimisation with Kyverno and VPA

The first talk was “Policy-Driven Cost Optimisation — With Kyverno & VPA”, given by a Senior Product Manager from Nirmata, one of the companies that maintain Kyverno. It started with an overview of Kyverno as the CNCF policy engine: policy-as-code to automate security and compliance; validate, mutate, cleanup and verifyImages rules; native exception management and reporting; integrated test tools; and support for any JSON payload.

Policy-Driven Cost Optimisation with Kyverno and VPA title slide at Platform Engineering Amsterdam, between the mogenius and tarmac banners

The title slide: Kyverno for policy, the Vertical Pod Autoscaler for right-sizing.

The talk was built around challenges and solutions. Challenge #2 was “Dynamic Workloads & Variable Utilisation”. A monitoring dashboard showed spiky usage graphs, the kind of pattern where a fixed request is either too big most of the time or too small at peak.

Challenge 2 Dynamic Workloads and Variable Utilisation slide with a monitoring dashboard at Platform Engineering Amsterdam

Challenge #2: dynamic workloads and variable utilisation.

The solutions came in steps. Step #1 was a diagram: when a Deployment, StatefulSet or DaemonSet goes through admission review, Kyverno generates a matching VPA for it. The slide’s bullets were “Auto-generate VPAs” and setting max limits based on requests. Step #3 was a ClusterCleanupPolicy (kyverno.io/v2alpha1) named pdb-cleanup. It matches PodDisruptionBudget resources whose target.status.disruptionsAllowed equals 0 and runs on the schedule "15 10,17 * * *", which the slide’s comment described as twice a day, at 10:15 and 17:15.

Solution Step 3 slide showing a Kyverno ClusterCleanupPolicy that removes PodDisruptionBudgets with zero disruptions allowed

Solution step #3: a scheduled Kyverno cleanup policy for PodDisruptionBudgets that allow zero disruptions.

My take: I liked this framing a lot. Most people only use Kyverno as a gatekeeper for security. Using generate to give every workload a VPA, and cleanup policies to remove things that get in the way of consolidation, turns the same engine into a FinOps tool. A PDB that allows zero disruptions can stop a node from ever draining, so a policy that finds them is worth having even if you don’t delete them automatically.

Building a platform team

The second talk was about organisation rather than YAML. Section 1 was “Shadow IT”, and its “Organization” slide had three points: embedded, find a backer, find a champion. Section 2 was “Platform team”, with a “Team/work” slide in four parts:

  1. Responsibilities: customer centric, growing over time
  2. Ownership: separation of concerns, modules
  3. Type of people: sysops, dev mindset
  4. Knowledge: cloud focused, automation

Section 2 Platform team Team/work slide listing responsibilities, ownership, type of people and knowledge

“Team/work”: responsibilities, ownership, type of people and knowledge.

My take: “find a backer, find a champion” is the part most platform teams skip. A platform that started as shadow IT only survives if someone with budget cares about it, and if at least one product team will publicly say it makes their life easier.

From free kicks to git commits

The third talk, “From free kicks to git commits”, was a personal one. The “My Story” slide was subtitled “A Journey of Passion, Setbacks, and Growth”. It traced a path from football to a career in cloud native. A second timeline, “Starting over: the tech journey begins”, went from starting from scratch, through embracing the challenge and finding a niche, to becoming a consultant and trainer, and “Now: continuous learning”.

From free kicks to git commits title slide at Platform Engineering Amsterdam with the speaker on stage

“From free kicks to git commits”: a career story from football to cloud native.

The technical part came back to the theme of the evening. The slide “Empowering developers through self service” put a platform at the centre, connected to Kubernetes, Terraform, Flux, Prometheus, Open Policy Agent, Backstage, Crossplane and GitHub. Two red slides near the end spoke to the audience directly: “You’re only as good as your ability to share your knowledge” and the question “Have you been working on anything exciting recently?”. The closing slide said “Bedankt!”.

Empowering developers through self service slide with a platform at the centre connected to Kubernetes, Terraform, Flux, Prometheus, Open Policy Agent, Backstage, Crossplane and GitHub

The platform in the middle, with Kubernetes, GitOps, IaC, policy, observability and a portal around it.

What’s next

The evening closed with an “Upcoming Recommended Events” slide: a meetup on 13 February (17:00–20:00), a webinar on 5 March (16:00–17:00) called “Practical Cloud Cost Control: Insights & Strategies”, and FastFlowConf on 27 March. After the talks there was food, and the conversations carried on around the tables.

Upcoming Recommended Events slide at Platform Engineering Amsterdam listing a meetup, a cloud cost control webinar and FastFlowConf

Upcoming events: a meetup, a cloud cost webinar and FastFlowConf.

All three talks came back to the same idea: self-service has to be cheap to run, owned by a real team, and taught by people willing to share what they know. Kyverno and VPA covered the first, the platform-team talk the second, and the free kicks story the third.

Free 30-min Production AI consultation

Book Now