
This patch set adds in the egress policy for core OpenStack Services. Depends-On: https://review.opendev.org/#/c/679853/ Change-Id: I585ddabcbd640db784520c913af8eddecaee3843 Signed-off-by: Tin Lam <tlam@omegaprime.dev>
49 lines
1.1 KiB
YAML
49 lines
1.1 KiB
YAML
manifests:
|
|
network_policy: true
|
|
#NOTE(gagehugo): Test these once the netpol gate works
|
|
network_policy:
|
|
heat:
|
|
# ingress:
|
|
# - from:
|
|
# - podSelector:
|
|
# matchLabels:
|
|
# application: heat
|
|
# - podSelector:
|
|
# matchLabels:
|
|
# application: ingress
|
|
# - podSelector:
|
|
# matchLabels:
|
|
# application: horizon
|
|
# ports:
|
|
# - protocol: TCP
|
|
# port: 80
|
|
# - protocol: TCP
|
|
# port: 8000
|
|
# - protocol: TCP
|
|
# port: 8003
|
|
# - protocol: TCP
|
|
# port: 8004
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
application: neutron
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
application: nova
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
application: glance
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
application: cinder
|
|
- to:
|
|
- ipBlock:
|
|
cidr: $API_ADDR/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: $API_PORT
|