Skip to content

Conversation

@elhamafzalizadeh
Copy link

@elhamafzalizadeh elhamafzalizadeh commented Dec 31, 2025

Gatekeeper Policy: K8sNodePortNamespaceRange

This is a Gatekeeper constraint that restricts the NodePort ranges based on team namespaces. Its purpose is to prevent accidental or uncoordinated NodePort assignments in the cluster.

Policy Details

  • apiVersion: constraints.gatekeeper.sh/v1beta1
  • kind: K8sNodePortNamespaceRange
  • metadata.name: enforce-nodeport-namespace-range
  • enforcementAction: deny (any Service violating this policy will be denied)

@elhamafzalizadeh elhamafzalizadeh requested a review from a team as a code owner December 31, 2025 11:35
@elhamafzalizadeh elhamafzalizadeh changed the title Add Gatekeeper example for NodePort namespace ranges feat: Add NodePort namespace range policy example Dec 31, 2025
@JaydipGabani
Copy link
Contributor

@elhamafzalizadeh https://github.com/open-policy-agent/gatekeeper-library is a good place to contribute new policies. Please raise a PR in the library repo and close this PR once you raise the one for library repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants