fix: add cilium cluster feature guards to network policies

This commit is contained in:
2025-06-24 14:26:03 +02:00
parent 4cff341fb0
commit d5e0da1692
78 changed files with 158 additions and 2 deletions
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: ingress-nginx io.kubernetes.pod.namespace: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/component: notifications-controller app.kubernetes.io/component: notifications-controller
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/component: applicationset-controller app.kubernetes.io/component: applicationset-controller
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/component: repo-server app.kubernetes.io/component: repo-server
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: ingress-nginx io.kubernetes.pod.namespace: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: argocd-image-updater app.kubernetes.io/name: argocd-image-updater
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: ingress-nginx io.kubernetes.pod.namespace: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
protocol: TCP protocol: TCP
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: argocd-dex-server app.kubernetes.io/name: argocd-dex-server
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -16,3 +17,4 @@ spec:
- ports: - ports:
- port: "8090" - port: "8090"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -16,3 +17,4 @@ spec:
- ports: - ports:
- port: "9090" - port: "9090"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -28,3 +29,4 @@ spec:
protocol: TCP protocol: TCP
- port: "5558" - port: "5558"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
# apiVersion: cilium.io/v2 # apiVersion: cilium.io/v2
# kind: CiliumNetworkPolicy # kind: CiliumNetworkPolicy
# metadata: # metadata:
@@ -13,3 +14,4 @@
# - ports: # - ports:
# - port: "6443" # - port: "6443"
# protocol: TCP # protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -9,3 +10,4 @@ spec:
- matchName: id.barentswatch.no - matchName: id.barentswatch.no
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -10,3 +11,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: atlantis app.kubernetes.io/name: atlantis
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
# apiVersion: cilium.io/v2 # apiVersion: cilium.io/v2
# kind: CiliumClusterwideNetworkPolicy # kind: CiliumClusterwideNetworkPolicy
# metadata: # metadata:
@@ -23,3 +24,4 @@
# # - matchPattern: '*.gitlab.com' # # - matchPattern: '*.gitlab.com'
# endpointSelector: # endpointSelector:
# matchLabels: {} # matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
ingress: ingress:
- fromEntities: - fromEntities:
- remote-node - remote-node
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -10,3 +11,4 @@ spec:
- kube-apiserver - kube-apiserver
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -16,3 +17,4 @@ spec:
- ports: - ports:
- port: "9402" - port: "9402"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -10,3 +11,4 @@ spec:
- world - world
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: v1 apiVersion: v1
kind: ConfigMap kind: ConfigMap
metadata: metadata:
@@ -1112,3 +1113,4 @@ data:
"version": 1, "version": 1,
"weekStart": "" "weekStart": ""
} }
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
{{if .Values.cilium.loadbalancerPool.enabled }} {{if .Values.cilium.loadbalancerPool.enabled }}
apiVersion: "cilium.io/v2alpha1" apiVersion: "cilium.io/v2alpha1"
kind: CiliumLoadBalancerIPPool kind: CiliumLoadBalancerIPPool
@@ -21,3 +22,4 @@ spec:
externalIPs: true externalIPs: true
loadBalancerIPs: true loadBalancerIPs: true
{{- end}} {{- end}}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
ingress: ingress:
- fromEntities: - fromEntities:
- remote-node - remote-node
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
protocol: TCP protocol: TCP
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
- ports: - ports:
- port: "8081" - port: "8081"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: "cilium.io/v2" apiVersion: "cilium.io/v2"
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -26,3 +27,4 @@ spec:
- toEntities: - toEntities:
- remote-node - remote-node
endpointSelector: {} endpointSelector: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
- ports: - ports:
- port: "6443" - port: "6443"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
- ports: - ports:
- port: "4000" - port: "4000"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
matchLabels: matchLabels:
app.kubernetes.io/component: controller app.kubernetes.io/component: controller
app.kubernetes.io/instance: ingress-nginx app.kubernetes.io/instance: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
matchLabels: matchLabels:
app.kubernetes.io/component: controller app.kubernetes.io/component: controller
app.kubernetes.io/instance: ingress-nginx app.kubernetes.io/instance: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -15,3 +16,4 @@ spec:
- ports: - ports:
- port: "9913" - port: "9913"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -17,3 +18,4 @@ spec:
matchLabels: matchLabels:
app.kubernetes.io/component: controller app.kubernetes.io/component: controller
app.kubernetes.io/instance: ingress-nginx app.kubernetes.io/instance: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -17,3 +18,4 @@ spec:
protocol: TCP protocol: TCP
- port: "443" - port: "443"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -16,3 +17,4 @@ spec:
matchLabels: matchLabels:
app.kubernetes.io/component: backend app.kubernetes.io/component: backend
app.kubernetes.io/instance: loki app.kubernetes.io/instance: loki
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -18,3 +19,4 @@ spec:
protocol: TCP protocol: TCP
- port: "3500" - port: "3500"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -15,3 +16,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: promtail app.kubernetes.io/instance: promtail
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -10,3 +11,4 @@ spec:
- 10.255.241.30/32 - 10.255.241.30/32
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: loki app.kubernetes.io/instance: loki
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: loki app.kubernetes.io/instance: loki
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
ingress: ingress:
- fromEntities: - fromEntities:
- world - world
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,4 +12,5 @@ spec:
- matchName: raw.githubusercontent.com - matchName: raw.githubusercontent.com
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: plausible-analytics app.kubernetes.io/name: plausible-analytics
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,4 +13,5 @@ spec:
- matchName: www.gravatar.com - matchName: www.gravatar.com
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: plausible-analytics app.kubernetes.io/name: plausible-analytics
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: postgres-operator app.kubernetes.io/instance: postgres-operator
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
- ports: - ports:
- port: "9443" - port: "9443"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: prom-alertmanager app.kubernetes.io/instance: prom-alertmanager
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: ingress-nginx io.kubernetes.pod.namespace: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: prometheus app.kubernetes.io/name: prometheus
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: prometheus app.kubernetes.io/name: prometheus
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: ingress-nginx io.kubernetes.pod.namespace: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: grafana app.kubernetes.io/name: grafana
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: grafana app.kubernetes.io/name: grafana
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: grafana app.kubernetes.io/name: grafana
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- kube-apiserver - kube-apiserver
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: ingress-nginx io.kubernetes.pod.namespace: ingress-nginx
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -17,3 +18,4 @@ spec:
- ports: - ports:
- port: "9090" - port: "9090"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
ingress: ingress:
- fromEntities: - fromEntities:
- remote-node - remote-node
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
ingress: ingress:
- fromEntities: - fromEntities:
- remote-node - remote-node
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
- fromEndpoints: - fromEndpoints:
- matchLabels: - matchLabels:
io.kubernetes.pod.namespace: robusta io.kubernetes.pod.namespace: robusta
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -10,3 +11,4 @@ spec:
- matchName: hooks.slack.com - matchName: hooks.slack.com
endpointSelector: endpointSelector:
matchLabels: {} matchLabels: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -11,3 +12,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/name: grafana app.kubernetes.io/name: grafana
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -50,3 +51,4 @@ spec:
- port: "35680" - port: "35680"
- port: "35681" - port: "35681"
- port: "35682" - port: "35682"
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -16,3 +17,4 @@ spec:
- ports: - ports:
- port: "15672" - port: "15672"
- port: "15671" - port: "15671"
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -25,3 +26,4 @@ spec:
- port: "15675" - port: "15675"
- port: "15692" - port: "15692"
- port: "15691" - port: "15691"
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -15,3 +16,4 @@ spec:
- port: "15672" - port: "15672"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -13,3 +14,4 @@ spec:
protocol: TCP protocol: TCP
endpointSelector: {} endpointSelector: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -15,3 +16,4 @@ spec:
# protocol: TCP # protocol: TCP
endpointSelector: {} endpointSelector: {}
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -8,3 +9,4 @@ spec:
- toFQDNs: - toFQDNs:
- matchName: login.microsoftonline.com - matchName: login.microsoftonline.com
- matchPattern: '*.microsoftonline.com' - matchPattern: '*.microsoftonline.com'
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -8,3 +9,4 @@ spec:
egress: egress:
- toEntities: - toEntities:
- kube-apiserver - kube-apiserver
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -20,3 +21,4 @@ spec:
protocol: TCP protocol: TCP
- port: "30080" - port: "30080"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -26,3 +27,4 @@ spec:
rules: rules:
dns: dns:
- matchPattern: "*" - matchPattern: "*"
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -10,3 +11,4 @@ spec:
- matchPattern: "*oceanbox.io" - matchPattern: "*oceanbox.io"
- matchPattern: "*.oceanbox.io" - matchPattern: "*.oceanbox.io"
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy kind: CiliumClusterwideNetworkPolicy
metadata: metadata:
@@ -8,3 +9,4 @@ spec:
ingress: ingress:
- fromEntities: - fromEntities:
- kube-apiserver - kube-apiserver
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -12,3 +13,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: tempo app.kubernetes.io/instance: tempo
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: velero app.kubernetes.io/instance: velero
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
batch.kubernetes.io/job-name: velero-upgrade-crds batch.kubernetes.io/job-name: velero-upgrade-crds
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -15,3 +16,4 @@ spec:
- ports: - ports:
- port: "8085" - port: "8085"
protocol: TCP protocol: TCP
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -14,3 +15,4 @@ spec:
endpointSelector: endpointSelector:
matchLabels: matchLabels:
app.kubernetes.io/instance: x509-exporter app.kubernetes.io/instance: x509-exporter
{{- end }}
@@ -1,3 +1,4 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2 apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy kind: CiliumNetworkPolicy
metadata: metadata:
@@ -15,3 +16,4 @@ spec:
- ports: - ports:
- port: "9793" - port: "9793"
protocol: TCP protocol: TCP
{{- end }}