apiVersion: kyverno.io/v2
kind: PolicyException
metadata:
  name: pod-security-exception
  namespace: policy-exception-ns
spec:
  exceptions:
  - policyName: psa-1
    ruleNames:
    - restricted
  match:
    any:
    - resources:
        namespaces:
        - staging-ns
  podSecurity:
    - controlName: Capabilities
      images:
          - nginx*
          - redis*