--- apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: check-node-port spec: admission: true background: true rules: - match: any: - resources: kinds: - Service name: check-node-port validate: message: NodePort type is not allowed pattern: spec: type: '!NodePort' validationFailureAction: Audit