Files

61 lines
1.7 KiB
YAML
Raw Permalink Normal View History

# 控制面 NetworkPolicy(docs/k8s.md §4.2 尾部)。若 namespace 走 default-deny
# (Cilium/Terway DataPath V2 下可能默认放行,则本文件为显式白名单、无害)。
# ingress:Traefik/Ingress → 3080;egress:Postgres:5432 + K8s API:443 + DNS:53
# + 每用户 DSH sidecar:8081 + 每用户 file sidecar:8082。控制面不回调任何公网。
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: dsh-orchestrator
namespace: dsh
spec:
podSelector:
matchLabels:
app: dsh-orchestrator
policyTypes: [Ingress, Egress]
ingress:
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: ingress-nginx
- namespaceSelector: {}
ports:
- port: 3080
egress:
- to:
- podSelector:
matchLabels:
cnpg.io/cluster: dsh-pg
ports:
- port: 5432
- to:
- podSelector:
matchLabels:
app: dsh
ports:
- port: 8081
- to:
- podSelector:
matchLabels:
app: dsh-files
ports:
- port: 8082
- to:
- namespaceSelector: {}
podSelector:
matchLabels:
k8s-app: kube-dns
ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
# K8s API server(托管的 control plane 在集群外,走公网/内网 API endpoint,
# 端口 6443/443)。这里放全出口 6443+443 以便访问 API server;如需更严,
# 按集群 API endpoint IP/CIDR 收窄。
- to:
- ipBlock:
cidr: 0.0.0.0/0
except: [169.254.169.254/32]
ports:
- port: 6443
- port: 443