Skip to content

Commit 33b40e4

Browse files
committed
Add default NetworkPolicies for HyperShift environments
1 parent bc5af87 commit 33b40e4

2 files changed

Lines changed: 38 additions & 0 deletions

File tree

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
kind: NetworkPolicy
2+
apiVersion: networking.k8s.io/v1
3+
metadata:
4+
name: network-node-identity
5+
namespace: {{.HostedClusterNamespace}}
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
app: network-node-identity
10+
policyTypes:
11+
- Ingress
12+
- Egress
13+
ingress:
14+
# Allow to webhook
15+
- ports:
16+
- port: {{.NetworkNodeIdentityPort}}
17+
egress:
18+
# Allow to apiserver
19+
- {}
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
kind: NetworkPolicy
2+
apiVersion: networking.k8s.io/v1
3+
metadata:
4+
name: ovn-kubernetes
5+
namespace: openshift-ovn-kubernetes
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
app: ovnkube-control-plane
10+
policyTypes:
11+
- Ingress
12+
- Egress
13+
ingress:
14+
# Allow ingress to metrics
15+
- ports:
16+
- port: 9108
17+
egress:
18+
# Allow egress to apiserver, and to ovnkube-node's egressip-node-healthcheck-port
19+
- {}

0 commit comments

Comments
 (0)