Files
openstack-helm/heat/values_overrides/netpol.yaml
Tin Lam a25eccb7cb Implements egress network policy
This patch set adds in the egress policy for core OpenStack Services.

Depends-On: https://review.opendev.org/#/c/679853/

Change-Id: I585ddabcbd640db784520c913af8eddecaee3843
Signed-off-by: Tin Lam <tlam@omegaprime.dev>
2019-11-22 01:16:49 +00:00

49 lines
1.1 KiB
YAML

manifests:
network_policy: true
#NOTE(gagehugo): Test these once the netpol gate works
network_policy:
heat:
# ingress:
# - from:
# - podSelector:
# matchLabels:
# application: heat
# - podSelector:
# matchLabels:
# application: ingress
# - podSelector:
# matchLabels:
# application: horizon
# ports:
# - protocol: TCP
# port: 80
# - protocol: TCP
# port: 8000
# - protocol: TCP
# port: 8003
# - protocol: TCP
# port: 8004
egress:
- to:
- podSelector:
matchLabels:
application: neutron
- to:
- podSelector:
matchLabels:
application: nova
- to:
- podSelector:
matchLabels:
application: glance
- to:
- podSelector:
matchLabels:
application: cinder
- to:
- ipBlock:
cidr: $API_ADDR/32
ports:
- protocol: TCP
port: $API_PORT