Skip to content

Conversation

@YuryHrytsuk
Copy link
Collaborator

@YuryHrytsuk YuryHrytsuk commented Aug 8, 2025

What do these changes do?

Apply global deny all traefik policy on cert-manager applications and add explicit network policy allowing necessary networking by extending existing chart with network policy (create a new chart with cert-manager as a subchart)

@sanderegg something not existing in docker swarm 😉

Implementation

Tasks:

  • Update calico global policy
  • Add policy for local deployment (existing policy fits)

Wishes:

  • restart cert manager components on policy change --> no easy way to do it (if there is any) + changes are not expected to happen frequently (or at all). Stay with manual restart

Related issue/s

Related PR/s

Checklist

  • I tested and it works

@YuryHrytsuk YuryHrytsuk marked this pull request as ready for review August 12, 2025 09:58
Copy link
Member

@mrnicegyu11 mrnicegyu11 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm thx!

@YuryHrytsuk YuryHrytsuk merged commit 4b4e1f7 into ITISFoundation:main Aug 13, 2025
3 checks passed
@YuryHrytsuk YuryHrytsuk deleted the kubernetes-cert-manager-network-policy branch August 13, 2025 09:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants