apiVersion: kyverno.io/v1alpha1 kind: ClusterPolicy metadata: name: validate-hostpid-hostipc annotations: policies.kyverno.io/category: Security policies.kyverno.io/description: Deny visibility of process on the host via hostPID, disable a process to communicate with processes on the host via hostIPC spec: rules: - name: validate-hostpid-hostipc match: resources: kinds: - Pod validate: message: "Disallow use of host's pid namespace and host's ipc namespace" pattern: spec: (hostPID): "!true" hostIPC: false