Symptoms:
apiVersion: policy/v1beta1kind: PodSecurityPolicymetadata:name: ncp-pspspec:hostNetwork: truehostIPC: falsehostPID: falseprivileged: falsedefaultAddCapabilities: nullVMware NSX-T Data Center
This capability was incorrectly omitted from the configuration file.
This issue is resolved in NCP 3.1.2.
Workaround:
You can manually add the capability to the file like the following:apiVersion: policy/v1beta1kind: PodSecurityPolicymetadata:name: ncp-pspspec:hostNetwork: truehostIPC: falsehostPID: falseprivileged: falsedefaultAddCapabilities: nullallowedCapabilities:- AUDIT_WRITE