Skip to content

Commit 6628d66

Browse files
committed
adds network policy for operator
1 parent d93408e commit 6628d66

File tree

8 files changed

+193
-1
lines changed

8 files changed

+193
-1
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: operator-allow-egress-to-api-server
5+
namespace: cert-manager-operator
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
name: cert-manager-operator
10+
policyTypes:
11+
- Egress
12+
egress:
13+
- ports:
14+
- protocol: TCP
15+
port: 6443
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: operator-allow-ingress-to-metrics
5+
namespace: cert-manager-operator
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
name: cert-manager-operator
10+
policyTypes:
11+
- Ingress
12+
ingress:
13+
- ports:
14+
- protocol: TCP
15+
port: 8443
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: operator-deny-all-traffic
5+
namespace: cert-manager-operator
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
name: cert-manager-operator
10+
policyTypes:
11+
- Ingress
12+
- Egress

pkg/controller/deployment/cert_manager_controller_set.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ type CertManagerControllerSet struct {
2121
certManagerWebhookDeploymentController factory.Controller
2222
certManagerCAInjectorStaticResourcesController factory.Controller
2323
certManagerCAInjectorDeploymentController factory.Controller
24+
certManagerOperatorStaticResourcesController factory.Controller
2425
}
2526

2627
func NewCertManagerControllerSet(
@@ -44,6 +45,7 @@ func NewCertManagerControllerSet(
4445
certManagerWebhookDeploymentController: NewCertManagerWebhookDeploymentController(operatorClient, certManagerOperatorInformers, infraInformers, kubeClient, kubeInformersForTargetNamespace, eventRecorder, targetVersion, versionRecorder, trustedCAConfigmapName, cloudCredentialsSecretName),
4546
certManagerCAInjectorStaticResourcesController: NewCertManagerCAInjectorStaticResourcesController(operatorClient, kubeClientContainer, kubeInformersForNamespaces, eventRecorder),
4647
certManagerCAInjectorDeploymentController: NewCertManagerCAInjectorDeploymentController(operatorClient, certManagerOperatorInformers, infraInformers, kubeClient, kubeInformersForTargetNamespace, eventRecorder, targetVersion, versionRecorder, trustedCAConfigmapName, cloudCredentialsSecretName),
48+
certManagerOperatorStaticResourcesController: NewCertManagerOperatorStaticResourcesController(operatorClient, kubeClientContainer, kubeInformersForNamespaces, eventRecorder),
4749
}
4850
}
4951

@@ -55,5 +57,6 @@ func (c *CertManagerControllerSet) ToArray() []factory.Controller {
5557
c.certManagerWebhookDeploymentController,
5658
c.certManagerCAInjectorStaticResourcesController,
5759
c.certManagerCAInjectorDeploymentController,
60+
c.certManagerOperatorStaticResourcesController,
5861
}
5962
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
package deployment
2+
3+
import (
4+
"github.com/openshift/library-go/pkg/controller/factory"
5+
"github.com/openshift/library-go/pkg/operator/events"
6+
"github.com/openshift/library-go/pkg/operator/resource/resourceapply"
7+
"github.com/openshift/library-go/pkg/operator/staticresourcecontroller"
8+
"github.com/openshift/library-go/pkg/operator/v1helpers"
9+
10+
"github.com/openshift/cert-manager-operator/pkg/operator/assets"
11+
)
12+
13+
const (
14+
certManagerOperatorStaticResourcesControllerName = operatorName + "-operator-static-resources-"
15+
)
16+
17+
var (
18+
certManagerOperatorAssetFiles = []string{
19+
"cert-manager-deployment/network-policy/operator-allow-egress-to-api-server.yaml",
20+
"cert-manager-deployment/network-policy/operator-allow-ingress-to-metrics.yaml",
21+
"cert-manager-deployment/network-policy/operator-deny-all-pod-selector.yaml",
22+
}
23+
)
24+
25+
func NewCertManagerOperatorStaticResourcesController(operatorClient v1helpers.OperatorClient,
26+
kubeClientContainer *resourceapply.ClientHolder,
27+
kubeInformersForNamespaces v1helpers.KubeInformersForNamespaces,
28+
eventsRecorder events.Recorder,
29+
) factory.Controller {
30+
return staticresourcecontroller.NewStaticResourceController(
31+
certManagerOperatorStaticResourcesControllerName,
32+
assets.Asset,
33+
certManagerOperatorAssetFiles,
34+
kubeClientContainer,
35+
operatorClient,
36+
eventsRecorder,
37+
).AddKubeInformers(kubeInformersForNamespaces)
38+
}

pkg/operator/assets/bindata.go

Lines changed: 103 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
package operatorclient
22

33
const (
4-
TargetNamespace = "cert-manager"
4+
TargetNamespace = "cert-manager"
5+
)
6+
7+
var (
58
OperatorNamespace = "cert-manager-operator"
69
)

pkg/operator/starter.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,10 +71,13 @@ func RunOperator(ctx context.Context, cc *controllercmd.ControllerContext) error
7171
versionRecorder := status.NewVersionGetter()
7272
versionRecorder.SetVersion("operator", status.VersionForOperatorFromEnv())
7373

74+
operatorclient.OperatorNamespace = cc.OperatorNamespace
75+
7476
kubeInformersForNamespaces := v1helpers.NewKubeInformersForNamespaces(kubeClient,
7577
"",
7678
"kube-system",
7779
operatorclient.TargetNamespace,
80+
operatorclient.OperatorNamespace,
7881
)
7982

8083
configClient, err := configv1client.NewForConfig(cc.KubeConfig)

0 commit comments

Comments
 (0)