metadata: name: restrict-host-access spec: selector: matchLabels: app: my-app process: matchPaths: - path: /proc/* file: matchPaths: - path: /host-mount capabilities: restrictedCapabilities: - SYS_ADMIN custom: - name: NoHostNetworking matchSyscalls: - name: setns action: Block matchPathCalled: - path: /proc/1/ns/ action: Block - name: NoNewPrivileges matchSyscalls: - name: clone action: Block args: [CLONE_NEWUSER, CLONE_NEWIPC, CLONE_NEWNET, CLONE_NEWPID, CLONE_NEWNS, CLONE_NEWUTS, CLONE_NEWCGROUP]