Commit 132edf3
fix(openshift): add NetworkPolicy for webhook access in mesh-enrolled namespaces
When ServiceMesh enrolls knative-serving via SMMR, it creates a deny-all
NetworkPolicy that blocks API server -> webhook traffic on multi-node
clusters. This causes KnativeServing install to fail with webhook timeout
errors. On SNC this was masked because all traffic is node-local.
Add a NetworkPolicy allowing ingress to webhook pods on port 8443 before
creating the Knative CR, so admission webhooks remain reachable regardless
of mesh network policies.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 360527f commit 132edf3
1 file changed
Lines changed: 31 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
100 | 101 | | |
101 | 102 | | |
102 | 103 | | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
103 | 134 | | |
104 | 135 | | |
105 | 136 | | |
| |||
0 commit comments