Skip to content

Commit 486e80f

Browse files
authored
update network policy for opensearch/elasticsearch (#2542)
* update network policy for opensearch Signed-off-by: Daniel Fan <[email protected]> * Add component label to NetworkPolicy resources for Flink and OpenSearch Signed-off-by: Daniel Fan <[email protected]> --------- Signed-off-by: Daniel Fan <[email protected]>
1 parent a6c7e5b commit 486e80f

9 files changed

+62
-10
lines changed

cp3-networkpolicy/egress/flink/bedrock-egress-ibm-flink-operand.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: egress-ibm-flink-operand
55
namespace: "flinkNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:

cp3-networkpolicy/egress/flink/bedrock-egress-ibm-flink-operator.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: egress-ibm-flink-operator
55
namespace: "opNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:

cp3-networkpolicy/egress/opensearch/bedrock-egress-ibm-opensearch-operand.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: egress-ibm-opensearch-operand
55
namespace: "opensearchNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:

cp3-networkpolicy/egress/opensearch/bedrock-egress-ibm-opensearch-operator.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: egress-ibm-opensearch-operator
55
namespace: "opNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:

cp3-networkpolicy/ingress/flink/bedrock-access-to-ibm-flink-operand.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: ingress-ibm-flink-operand
55
namespace: "flinkNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:

cp3-networkpolicy/ingress/flink/bedrock-access-to-ibm-flink-operator.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: ingress-ibm-flink-operator
55
namespace: "opNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
kind: NetworkPolicy
2+
apiVersion: networking.k8s.io/v1
3+
metadata:
4+
name: ingress-ibm-elasticsearch-operand
5+
namespace: "opensearchNamespace"
6+
labels:
7+
component: cpfs3
8+
spec:
9+
podSelector:
10+
matchLabels:
11+
app.kubernetes.io/managed-by: ibm-elasticsearch
12+
ingress:
13+
- ports:
14+
- protocol: TCP
15+
port: 443
16+
- protocol: TCP
17+
port: 19300
18+
- protocol: TCP
19+
port: 9300
20+
- protocol: TCP
21+
port: 9200
22+
from:
23+
- podSelector: {}
24+
policyTypes:
25+
- Ingress

cp3-networkpolicy/ingress/opensearch/bedrock-access-to-ibm-opensearch-operand.yaml

Lines changed: 23 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -3,21 +3,34 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: ingress-ibm-opensearch-operand
55
namespace: "opensearchNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:
9-
app.kubernetes.io/managed-by: ibm-elasticsearch
11+
cluster.opensearch.cloudpackopen.ibm.com: opensearch-cr
1012
ingress:
1113
- ports:
12-
- protocol: TCP
13-
port: 443
14-
- protocol: TCP
15-
port: 19300
16-
- protocol: TCP
17-
port: 9300
18-
- protocol: TCP
19-
port: 9200
14+
- protocol: TCP
15+
port: 9200
16+
endPort: 9300
17+
- protocol: TCP
18+
port: 9300
19+
endPort: 9400
2020
from:
21-
- podSelector: {}
21+
- podSelector:
22+
matchLabels:
23+
cluster.opensearch.cloudpackopen.ibm.com: opensearch-cr
24+
- ports:
25+
- protocol: TCP
26+
port: 9200
27+
- protocol: TCP
28+
port: 2112
29+
- protocol: TCP
30+
port: 9300
31+
from:
32+
- namespaceSelector:
33+
matchLabels:
34+
kubernetes.io/metadata.name: "opensearchNamespace"
2235
policyTypes:
2336
- Ingress

cp3-networkpolicy/ingress/opensearch/bedrock-access-to-ibm-opensearch-operator.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ apiVersion: networking.k8s.io/v1
33
metadata:
44
name: ingress-ibm-opensearch-operator
55
namespace: "opNamespace"
6+
labels:
7+
component: cpfs3
68
spec:
79
podSelector:
810
matchLabels:

0 commit comments

Comments
 (0)