apiVersion: kyverno.io/v1alpha1 kind: ClusterPolicy metadata: name: validate-hostpid-hostipc spec: rules: - name: validate-hostpid-hostipc match: resources: kinds: - Pod validate: message: "Disallow use of host's pid namespace and host's ipc namespace" pattern: spec: (hostPID): "!true" hostIPC: false