--- apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: check-registries spec: admission: true background: true rules: - match: any: - resources: kinds: - Deployment - StatefulSet name: check-registries validate: message: Registry is not allowed pattern: spec: template: spec: containers: - image: '*/nirmata/* | https://private.registry.io/*' name: '*' validationFailureAction: Audit