Cookbook¶ Worked examples — full rules you can copy, adapt, and apply. Disallow privileged Enforce labels Require PDB per Deployment Allowed registries Non-root containers NetworkPolicy default-deny Quarantine on violation Revoke SA token on exec (v2)