apiVersion: kyverno.io/v1alpha1 kind: ClusterPolicy metadata: name: validate-default-proc-mount spec: validationFailureAction: "audit" rules: - name: validate-default-proc-mount match: resources: kinds: - Pod validate: message: "Default proc mount should set to Unmasked" pattern: spec: containers: - securityContext: procMount: Unmasked # used by rootless containers