pkg/manifests/policy/manifests/k8spspforbiddensysctls.yaml (12 lines of code) (raw):

apiVersion: constraints.gatekeeper.sh/v1beta1 kind: K8sPSPForbiddenSysctls metadata: name: psp-forbidden-sysctls spec: match: kinds: - apiGroups: [""] kinds: ["Pod"] parameters: forbiddenSysctls: - "*"