Skip to content

Comments

Generate rclone network policies#2057

Merged
aarnq merged 1 commit intomainfrom
aarnq/rclone-netpol-gen
Apr 5, 2024
Merged

Generate rclone network policies#2057
aarnq merged 1 commit intomainfrom
aarnq/rclone-netpol-gen

Conversation

@aarnq
Copy link
Contributor

@aarnq aarnq commented Mar 22, 2024

Warning

This is a public repository, ensure not to disclose:

  • personal data beyond what is necessary for interacting with this pull request, nor
  • business confidential information, such as customer names.

What kind of PR is this?

Required: Mark one of the following that is applicable:

  • kind/feature
  • kind/improvement
  • kind/deprecation
  • kind/documentation
  • kind/clean-up
  • kind/bug
  • kind/other

Optional: Mark one or more of the following that are applicable:

Important

Breaking changes should be marked kind/admin-change or kind/dev-change depending on type
Critical security fixes should be marked with kind/security

  • kind/admin-change
  • kind/dev-change
  • kind/security
  • kind/adr

What does this PR do / why do we need this PR?

Final part of #1931, network policies for the new rclone restore (and update to rclone sync).

Information to reviewers

Now the objectStorage set both for main and sync will be the one that is configured as the type for them.
In https://github.com/elastisys/welkin-apps/issues/109 this will be further restricted so that the type s3+swift will be the type to allow Swift as an additional config.

Checklist

  • Proper commit message prefix on all commits
  • Change checks:
    • The change is transparent
    • The change is disruptive
    • The change requires no migration steps
    • The change requires migration steps
    • The change upgrades CRDs
  • Metrics checks:
    • The metrics are still exposed and present in Grafana after the change
    • The metrics names didn't change (Grafana dashboards and Prometheus alerts are not affected)
    • The metrics names did change (Grafana dashboards and Prometheus alerts were fixed)
  • Logs checks:
    • The logs do not show any errors after the change
  • Pod Security Policy checks:
    • Any changed pod is covered by Pod Security Admission
    • Any changed pod is covered by Gatekeeper Pod Security Policies
    • The change does not cause any pods to be blocked by Pod Security Admission or Policies
  • Network Policy checks:
    • Any changed pod is covered by Network Policies
    • The change does not cause any dropped packets in the NetworkPolicy Dashboard
  • Audit checks:
    • The change does not cause any unnecessary Kubernetes audit events
    • The change requires changes to Kubernetes audit policy
  • Falco checks:
    • The change does not cause any alerts to be generated by Falco
  • Bug checks:
    • The bug fix is covered by regression tests

@aarnq aarnq added the kind/improvement Improvement of existing features, e.g. code cleanup or optimizations. label Mar 22, 2024
@aarnq aarnq self-assigned this Mar 22, 2024
@aarnq aarnq changed the title apps sc: Generate rclone network policies Generate rclone network policies Mar 26, 2024
@aarnq aarnq marked this pull request as ready for review March 26, 2024 08:29
@aarnq aarnq force-pushed the aarnq/rclone-sync branch from 7e96d34 to 2e8d97b Compare April 5, 2024 11:16
@aarnq aarnq force-pushed the aarnq/rclone-netpol-gen branch 2 times, most recently from 70c005f to efb9c9d Compare April 5, 2024 12:05
@aarnq aarnq force-pushed the aarnq/rclone-sync branch from 2e8d97b to cd236d0 Compare April 5, 2024 12:17
Base automatically changed from aarnq/rclone-sync to main April 5, 2024 12:23
@aarnq aarnq force-pushed the aarnq/rclone-netpol-gen branch from efb9c9d to ee9083c Compare April 5, 2024 12:24
@aarnq aarnq merged commit ee9083c into main Apr 5, 2024
@aarnq aarnq deleted the aarnq/rclone-netpol-gen branch April 5, 2024 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/improvement Improvement of existing features, e.g. code cleanup or optimizations.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants