policyDefinitions/Kubernetes/forbidden-sysctl-interfaces/constraint.yaml (12 lines of code) (raw):

apiVersion: constraints.gatekeeper.sh/v1beta1 kind: K8sAzureForbiddenSysctls metadata: name: psp-forbidden-sysctls spec: match: excludedNamespaces: {{ .Values.excludedNamespaces }} kinds: - apiGroups: [""] kinds: ["Pod"] parameters: forbiddenSysctls: {{ .Values.forbiddenSysctls }}