apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: disallow-latest-tag spec: validationFailureAction: Audit rules: - match: any: - resources: kinds: - Pod - Deployment name: require-image-tag validate: message: An image tag is required. pattern: spec: containers: - image: '*:*' - match: any: - resources: kinds: - Pod name: validate-image-tag validate: message: Using a mutable image tag e.g. 'latest' is not allowed. pattern: spec: containers: - image: '!*:latest' status: conditions: - reason: Succeeded status: "True" type: Ready autogen: {}