Skip to content

Commit 6b845a2

Browse files
Merge pull request #395 from sunzhaohua2/policy
OCPCLOUD-2978: add deny all network policy
2 parents 7d34021 + 3c38945 commit 6b845a2

1 file changed

Lines changed: 32 additions & 0 deletions

File tree

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Default deny all ingress and egress traffic by default in this namespace
2+
# At the moment no other Network Policy should be needed:
3+
# - CCCMO & CCM pods are host-networked Pods, so they are not affected by network policies
4+
apiVersion: networking.k8s.io/v1
5+
kind: NetworkPolicy
6+
metadata:
7+
name: default-deny
8+
namespace: openshift-cloud-controller-manager-operator
9+
annotations:
10+
capability.openshift.io/name: CloudControllerManager
11+
include.release.openshift.io/self-managed-high-availability: "true"
12+
include.release.openshift.io/single-node-developer: "true"
13+
spec:
14+
podSelector: {}
15+
policyTypes:
16+
- Ingress
17+
- Egress
18+
---
19+
apiVersion: networking.k8s.io/v1
20+
kind: NetworkPolicy
21+
metadata:
22+
name: default-deny
23+
namespace: openshift-cloud-controller-manager
24+
annotations:
25+
capability.openshift.io/name: CloudControllerManager
26+
include.release.openshift.io/self-managed-high-availability: "true"
27+
include.release.openshift.io/single-node-developer: "true"
28+
spec:
29+
podSelector: {}
30+
policyTypes:
31+
- Ingress
32+
- Egress

0 commit comments

Comments
 (0)