apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: {{ include "flex-auth.name" . }} labels: {{- include "flex-auth.labels" . | nindent 4 }} spec: podSelector: matchLabels: {{- include "flex-auth.selectorLabels" . | nindent 6 }} policyTypes: - Ingress - Egress {{- if eq (include "flex-auth.callerAuth.enabled" .) "true" }} egress: - ports: - port: 443 protocol: TCP - port: 6443 protocol: TCP {{- else }} egress: [] {{- end }} {{- if .Values.consumer.isolated }} ingress: [] {{- else }} ingress: - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: {{ required "consumer.namespace is required when not isolated" .Values.consumer.namespace }} podSelector: matchLabels: app.kubernetes.io/name: {{ required "consumer.podName is required when not isolated" .Values.consumer.podName }} ports: - port: {{ .Values.service.port }} protocol: TCP {{- end }}