apiVersion: kyverno.io/v2 kind: PolicyException metadata: creationTimestamp: null name: exception-2 spec: exceptions: - policyName: psa ruleNames: - restricted match: all: - resources: kinds: - Pod podSecurity: - controlName: "/proc Mount Type" images: - nginx restrictedField: "spec.containers[*].securityContext.procMount"