Skip to content

Commit ab54979

Browse files
authored
fix: add in missing ACLs for windows multitenancy (#2617)
* test: test conflist for windows multitenancy on an aks cluster * fix: add in allow acls
1 parent 988974f commit ab54979

File tree

2 files changed

+20
-1
lines changed

2 files changed

+20
-1
lines changed

cni/azure-windows-multitenancy.conflist

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,11 +55,29 @@
5555
"Priority": 200,
5656
"RuleType": "Switch"
5757
}
58+
},
59+
{
60+
"Name": "EndpointPolicy",
61+
"Value": {
62+
"Type": "ACL",
63+
"Action": "Allow",
64+
"Direction": "In",
65+
"Priority": 65500
66+
}
67+
},
68+
{
69+
"Name": "EndpointPolicy",
70+
"Value": {
71+
"Type": "ACL",
72+
"Action": "Allow",
73+
"Direction": "Out",
74+
"Priority": 65500
75+
}
5876
}
5977
],
6078
"windowsSettings": {
6179
"hnsTimeoutDurationInSeconds" : 120
6280
}
6381
}
6482
]
65-
}
83+
}

cni/windows.Dockerfile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ COPY --from=azure-vnet /azure-container-networking/cni/azure-$OS.conflist /paylo
2121
COPY --from=azure-vnet /azure-container-networking/cni/azure-$OS-swift.conflist /payload/azure-swift.conflist
2222
COPY --from=azure-vnet /azure-container-networking/cni/azure-$OS-swift-overlay.conflist /payload/azure-swift-overlay.conflist
2323
COPY --from=azure-vnet /azure-container-networking/cni/azure-$OS-swift-overlay-dualstack.conflist /payload/azure-swift-overlay-dualstack.conflist
24+
COPY --from=azure-vnet /azure-container-networking/cni/azure-$OS-multitenancy.conflist /payload/azure-multitenancy.conflist
2425
COPY --from=azure-vnet /azure-container-networking/telemetry/azure-vnet-telemetry.config /payload/azure-vnet-telemetry.config
2526
RUN cd /payload && sha256sum * > sum.txt
2627
RUN gzip --verbose --best --recursive /payload && for f in /payload/*.gz; do mv -- "$f" "${f%%.gz}"; done

0 commit comments

Comments
 (0)