Skip to content

Commit f7c6266

Browse files
test that host networked pods are not impacted by network policies
1 parent 7a8a698 commit f7c6266

File tree

3 files changed

+40
-0
lines changed

3 files changed

+40
-0
lines changed
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: kube-rbac-proxy-crio-deny-all
5+
namespace: openshift-machine-config-operator
6+
annotations:
7+
include.release.openshift.io/ibm-cloud-managed: "true"
8+
include.release.openshift.io/self-managed-high-availability: "true"
9+
include.release.openshift.io/single-node-developer: "true"
10+
spec:
11+
podSelector:
12+
matchLabels:
13+
k8s-app: kube-rbac-proxy-crio
14+
policyTypes:
15+
- Ingress
16+
- Egress
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: machine-config-daemon-deny-all
5+
namespace: {{.TargetNamespace}}
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
k8s-app: machine-config-daemon
10+
policyTypes:
11+
- Ingress
12+
- Egress
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: machine-config-server-deny-all
5+
namespace: {{.TargetNamespace}}
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
k8s-app: machine-config-server
10+
policyTypes:
11+
- Ingress
12+
- Egress

0 commit comments

Comments
 (0)