UNCLASSIFIED
Skip to content
GitLab
Projects
Groups
Snippets
Help
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in
Toggle navigation
Open sidebar
Platform One
Big Bang
P
Packages
Core
istio-controlplane
Commits
784ca1f7
Commit
784ca1f7
authored
Jul 08, 2021
by
Micah Nagel
💰
Browse files
clean up?
parent
c69c024f
Pipeline
#355840
passed with stages
in 1 minute and 41 seconds
Changes
11
Pipelines
1
Hide whitespace changes
Inline
Side-by-side
Showing
11 changed files
with
29 additions
and
12 deletions
+29
-12
chart/templates/network-policy/egress-default-deny.yaml
chart/templates/network-policy/egress-default-deny.yaml
+1
-1
chart/templates/network-policy/egress-dns.yaml
chart/templates/network-policy/egress-dns.yaml
+0
-0
chart/templates/network-policy/egress-gateway-external.yaml
chart/templates/network-policy/egress-gateway-external.yaml
+1
-1
chart/templates/network-policy/egress-virtual-services.yaml
chart/templates/network-policy/egress-virtual-services.yaml
+17
-0
chart/templates/network-policy/ingress-default-deny.yaml
chart/templates/network-policy/ingress-default-deny.yaml
+1
-1
chart/templates/network-policy/ingress-egress-inside-ns.yaml
chart/templates/network-policy/ingress-egress-inside-ns.yaml
+0
-0
chart/templates/network-policy/ingress-gateway-external.yaml
chart/templates/network-policy/ingress-gateway-external.yaml
+1
-1
chart/templates/network-policy/ingress-istio-enabled-ns.yaml
chart/templates/network-policy/ingress-istio-enabled-ns.yaml
+2
-2
chart/templates/network-policy/ingress-istio-enabled-pod.yaml
...t/templates/network-policy/ingress-istio-enabled-pod.yaml
+2
-2
chart/templates/network-policy/ingress-monitoring-istiod.yaml
...t/templates/network-policy/ingress-monitoring-istiod.yaml
+2
-2
chart/templates/network-policy/ingress-webhook.yaml
chart/templates/network-policy/ingress-webhook.yaml
+2
-2
No files found.
chart/templates/network-policy/egress-default-deny.yml
→
chart/templates/network-policy/egress-default-deny.y
a
ml
View file @
784ca1f7
...
...
@@ -2,7 +2,7 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
default-deny
-egress
name
:
egress-
default-deny
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
podSelector
:
{}
...
...
chart/templates/network-policy/egress-dns.yml
→
chart/templates/network-policy/egress-dns.y
a
ml
View file @
784ca1f7
File moved
chart/templates/network-policy/egress-gateway-external.yml
→
chart/templates/network-policy/egress-gateway-external.y
a
ml
View file @
784ca1f7
...
...
@@ -3,7 +3,7 @@ apiVersion: networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
# Note: This is not used currently since we don't have an egress gateway
name
:
egress-gateway-
allow
-external
-traffic
name
:
egress-gateway-
traffic-to
-external
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
egress
:
...
...
chart/templates/network-policy/egress-virtual-services.yaml
0 → 100644
View file @
784ca1f7
{{
- if .Values.networkPolicies.enabled
}}
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
egress-virtual-services
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
# Since we don't know what apps may have VS and what ports they are on, allow to all namespaces, any ports
egress
:
-
to
:
-
namespaceSelector
:
{}
podSelector
:
matchLabels
:
istio
:
ingressgateway
policyTypes
:
-
Egress
{{
- end
}}
chart/templates/network-policy/ingress-default-deny.yml
→
chart/templates/network-policy/ingress-default-deny.y
a
ml
View file @
784ca1f7
...
...
@@ -2,7 +2,7 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
default-deny
-ingress
name
:
ingress-
default-deny
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
podSelector
:
{}
...
...
chart/templates/network-policy/ingress-egress-inside-ns.yml
→
chart/templates/network-policy/ingress-egress-inside-ns.y
a
ml
View file @
784ca1f7
File moved
chart/templates/network-policy/ingress-gateway-external.yml
→
chart/templates/network-policy/ingress-gateway-external.y
a
ml
View file @
784ca1f7
...
...
@@ -2,7 +2,7 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
ingress-
gateway-allow-
external-traffic
name
:
ingress-external-traffic
-to-gateway
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
ingress
:
...
...
chart/templates/network-policy/ingress-istio-enabled-ns.yml
→
chart/templates/network-policy/ingress-istio-enabled-ns.y
a
ml
View file @
784ca1f7
...
...
@@ -2,7 +2,7 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
ingress-i
njection-enabl
ed-ns
name
:
ingress-i
stio-inject
ed-ns
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
ingress
:
...
...
@@ -15,7 +15,7 @@ spec:
protocol
:
TCP
podSelector
:
matchLabels
:
app
:
istiod
istio
:
pilot
policyTypes
:
-
Ingress
-
Egress
...
...
chart/templates/network-policy/ingress-istio-enabled-pod.yml
→
chart/templates/network-policy/ingress-istio-enabled-pod.y
a
ml
View file @
784ca1f7
...
...
@@ -2,7 +2,7 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
gateway
-istio-
enabl
ed-pods
name
:
ingress
-istio-
inject
ed-pods
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
ingress
:
...
...
@@ -16,7 +16,7 @@ spec:
protocol
:
TCP
podSelector
:
matchLabels
:
app
:
istiod
istio
:
pilot
policyTypes
:
-
Ingress
-
Egress
...
...
chart/templates/network-policy/ingress-monitoring-istiod.yml
→
chart/templates/network-policy/ingress-monitoring-istiod.y
a
ml
View file @
784ca1f7
...
...
@@ -2,7 +2,7 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
ingress-
istiod-allow-
metric-scraping
name
:
ingress-metric-scraping
namespace
:
"
{{
.Release.Namespace
}}"
spec
:
ingress
:
...
...
@@ -18,7 +18,7 @@ spec:
protocol
:
TCP
podSelector
:
matchLabels
:
app
:
istiod
istio
:
pilot
policyTypes
:
-
Ingress
{{
- end
}}
chart/templates/network-policy/ingress-webhook.yml
→
chart/templates/network-policy/ingress-webhook.y
a
ml
View file @
784ca1f7
...
...
@@ -2,12 +2,12 @@
apiVersion
:
networking.k8s.io/v1
kind
:
NetworkPolicy
metadata
:
name
:
ingress-
allow-
webhook
-api
name
:
ingress-webhook
namespace
:
{{
.Release.Namespace
}}
spec
:
podSelector
:
matchLabels
:
app
:
istiod
istio
:
pilot
ingress
:
-
from
:
-
ipBlock
:
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment