From e47a3272d32de66ade2fcf1ed16381fd18ad6d62 Mon Sep 17 00:00:00 2001 From: Branden Cobb Date: Wed, 2 Jun 2021 16:10:41 +0000 Subject: [PATCH 1/5] Update helm-test-network-policy.yaml --- .../networkpolicies/helm-test-network-policy.yaml | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml b/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml index fd3d356..2364497 100644 --- a/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml +++ b/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml @@ -16,11 +16,6 @@ spec: policyTypes: - Egress egress: - - to: - - ipBlock: - cidr: 0.0.0.0/0 - # ONLY Block requests to AWS metadata IP - except: - - 169.254.169.254/32 + - {} +{{- end }} {{- end }} -{{- end }} \ No newline at end of file -- GitLab From c8475d401dbe03ffb68d06631831eea47c625bb7 Mon Sep 17 00:00:00 2001 From: Branden Cobb Date: Wed, 2 Jun 2021 16:11:05 +0000 Subject: [PATCH 2/5] Update helm-test-network-policy.yaml --- .../bigbang/networkpolicies/helm-test-network-policy.yaml | 2 -- 1 file changed, 2 deletions(-) diff --git a/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml b/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml index 2364497..f84cae3 100644 --- a/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml +++ b/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml @@ -1,8 +1,6 @@ {{- $bbtests := .Values.bbtests | default dict -}} {{- $cypress := $bbtests.cypress | default dict -}} {{- $enabled := (hasKey $bbtests "enabled") -}} -{{- $artifacts := (hasKey $cypress "artifacts") -}} -{{- if and $enabled $artifacts }} {{- if and .Values.networkPolicies.enabled .Values.bbtests.enabled .Values.bbtests.cypress.artifacts }} apiVersion: networking.k8s.io/v1 kind: NetworkPolicy -- GitLab From 493a35573232ce7b066de404ba77c0f9fbf7bd84 Mon Sep 17 00:00:00 2001 From: Branden Cobb Date: Wed, 2 Jun 2021 17:13:53 +0000 Subject: [PATCH 3/5] Update helm-test-network-policy.yaml --- .../bigbang/networkpolicies/helm-test-network-policy.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml b/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml index f84cae3..319b034 100644 --- a/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml +++ b/chart/templates/bigbang/networkpolicies/helm-test-network-policy.yaml @@ -1,7 +1,7 @@ {{- $bbtests := .Values.bbtests | default dict -}} -{{- $cypress := $bbtests.cypress | default dict -}} {{- $enabled := (hasKey $bbtests "enabled") -}} -{{- if and .Values.networkPolicies.enabled .Values.bbtests.enabled .Values.bbtests.cypress.artifacts }} +{{- if $enabled }} +{{- if and .Values.networkPolicies.enabled .Values.bbtests.enabled }} apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: -- GitLab From 5f9eb5db88d33a3ed707aa9af995f6a50dcecbaa Mon Sep 17 00:00:00 2001 From: Branden Cobb Date: Wed, 2 Jun 2021 17:15:28 +0000 Subject: [PATCH 4/5] Update Chart.yaml --- chart/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 457eb03..162b121 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v1 appVersion: 8.7.1-community name: sonarqube description: SonarQube is an open sourced code quality scanning tool -version: 9.2.6-bb.11 +version: 9.2.6-bb.12 keywords: - coverage - security -- GitLab From 9d87a99a0bde59b82d78699582ba0a78c8ed254d Mon Sep 17 00:00:00 2001 From: Branden Cobb Date: Wed, 2 Jun 2021 17:16:08 +0000 Subject: [PATCH 5/5] Update CHANGELOG.md --- CHANGELOG.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3f42276..aea70d8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,10 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). --- +## [9.2.6-bb.12] - 2021-06-02 +### Modified +- Modified helm-test network policy to be more restrictive. + ## [9.2.6-bb.11] - 2021-05-27 ### Modified - Modified the bigbang monitoring network policy to be more restrictive. -- GitLab