apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: podsecurity-subrule-restricted spec: background: true rules: - name: restricted match: any: - resources: kinds: - Pod validate: failureAction: Audit podSecurity: level: restricted version: latest