Skip to content

feat: Implement default Secure Network Policy #263

@vicentefb

Description

@vicentefb

Currently, the SandboxClaim controller only creates a NetworkPolicy if the SandboxTemplate explicitly defines one.

In Reconcile, check if the SandboxTemplate has a NetworkPolicy defined.

Scenario A (No Policy): Create a default NetworkPolicy for this Sandbox that denies all Ingress/Egress (except necessary DNS/Proxy traffic).

Scenario B (User Policy): If a policy exists, ideally append a mandatory rule blocking (Metadata Server) to ensure even custom policies don't accidentally expose credentials.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions