Kubernetes: add cert-manager network policy
#1175
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What do these changes do?
Apply global deny all traefik policy on
cert-managerapplications and add explicit network policy allowing necessary networking by extending existing chart with network policy (create a new chart with cert-manager as a subchart)@sanderegg something not existing in docker swarm 😉
Implementation
Tasks:
Wishes:
restart cert manager components on policy change--> no easy way to do it (if there is any) + changes are not expected to happen frequently (or at all). Stay with manual restartRelated issue/s
Related PR/s
Checklist