apiVersion: kyverno.io/v2
kind: PolicyException
metadata:
  name: pod-security-exception
  namespace: policy-exception-ns
spec:
  exceptions:
  - policyName: psa
    ruleNames:
    - restricted
  match:
    any:
    - resources:
        namespaces:
        - staging-ns
  podSecurity:
    - controlName: "Seccomp"
      images:
      - nginx
      restrictedField: "spec.containers[*].securityContext.seccompProfile.type"
      values:
      - "Unconfined"