apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: psa spec: background: true validationFailureAction: Enforce rules: - name: restricted match: any: - resources: kinds: - Pod validate: podSecurity: level: restricted version: latest