apiVersion: kyverno.io/v1alpha1 kind: ClusterPolicy metadata: name: validate-container-capablities spec: validationFailureAction: "audit" rules: - name: validate-container-capablities match: resources: kinds: - Pod validate: message: "Allow certain capability to be added" pattern: spec: containers: - securityContext: capabilities: add: ["NET_ADMIN"]