apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: psa spec: background: true rules: - name: restricted match: any: - resources: kinds: - Pod validate: failureAction: Enforce podSecurity: level: restricted version: latest