9dfa06ffee
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
Signed-off-by: cls_宁波本机 <908705107@qq.com>
43 lines
1.8 KiB
YAML
43 lines
1.8 KiB
YAML
{{- if .Values.networkPolicy.enabled }}
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: {{ include "push.name" . }}
|
|
spec:
|
|
podSelector:
|
|
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
|
|
policyTypes: [Ingress, Egress]
|
|
ingress:
|
|
- ports: [{ port: 8080, protocol: TCP }]
|
|
{{- if .Values.networkPolicy.monitoring.enabled }}
|
|
{{- if or (not .Values.networkPolicy.monitoring.namespaceSelector) (not .Values.networkPolicy.monitoring.podSelector) }}
|
|
{{- fail "networkPolicy.monitoring.enabled requires non-empty namespaceSelector and podSelector so 8081 scrape ingress is scoped, never blanket" }}
|
|
{{- end }}
|
|
# Scoped scrape access to the private health/metrics port. Off by default so
|
|
# 8081 has no pod ingress; when enabled the operator names their scraper.
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels: {{- toYaml .Values.networkPolicy.monitoring.namespaceSelector | nindent 14 }}
|
|
podSelector:
|
|
matchLabels: {{- toYaml .Values.networkPolicy.monitoring.podSelector | nindent 14 }}
|
|
ports: [{ port: 8081, protocol: TCP }]
|
|
{{- end }}
|
|
egress:
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels: {{- toYaml .Values.networkPolicy.dns.namespaceSelector | nindent 14 }}
|
|
podSelector:
|
|
matchLabels: {{- toYaml .Values.networkPolicy.dns.podSelector | nindent 14 }}
|
|
ports: [{ port: 53, protocol: UDP }, { port: 53, protocol: TCP }]
|
|
- to:
|
|
{{- range .Values.networkPolicy.apnsEgressCidrs }}
|
|
- ipBlock: { cidr: {{ . }} }
|
|
{{- end }}
|
|
ports: [{ port: 443, protocol: TCP }]
|
|
- to:
|
|
{{- range .Values.networkPolicy.postgresEgressCidrs }}
|
|
- ipBlock: { cidr: {{ . }} }
|
|
{{- end }}
|
|
ports: [{ port: 5432, protocol: TCP }]
|
|
{{- end }}
|