access-engine/charts/flex-auth/templates/networkpolicy.yaml
tegwick fa278674c1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Pin caller-auth digest in warn on independently rollable overlay pins
The sanctioned Helm chart could not promote ADR 0004 at all, and the
emergency manifests selected enforce. That made a FLEX-WP-0011 apply
either a no-op or a global 401. First production pin is now warn, per
consumer, on CI digest sha256:138aa347… . Enforce stays a later
per-consumer flip so USER-WP-0023-T03 can close without waiting on
tenant-engine.
2026-08-19 12:31:08 +02:00

38 lines
1 KiB
YAML

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "flex-auth.name" . }}
labels:
{{- include "flex-auth.labels" . | nindent 4 }}
spec:
podSelector:
matchLabels:
{{- include "flex-auth.selectorLabels" . | nindent 6 }}
policyTypes:
- Ingress
- Egress
{{- if eq (include "flex-auth.callerAuth.enabled" .) "true" }}
egress:
- ports:
- port: 443
protocol: TCP
- port: 6443
protocol: TCP
{{- else }}
egress: []
{{- end }}
{{- if .Values.consumer.isolated }}
ingress: []
{{- else }}
ingress:
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: {{ required "consumer.namespace is required when not isolated" .Values.consumer.namespace }}
podSelector:
matchLabels:
app.kubernetes.io/name: {{ required "consumer.podName is required when not isolated" .Values.consumer.podName }}
ports:
- port: {{ .Values.service.port }}
protocol: TCP
{{- end }}