In the podsecuritypolicy the following entry should be preserved by default:
requiredDropCapabilities:
- ALL