Skip to content

Commit 9864f42

Browse files
committed
adds network policy for operator
1 parent f03287e commit 9864f42

File tree

8 files changed

+206
-1
lines changed

8 files changed

+206
-1
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: operator-allow-egress-to-api-server
5+
namespace: ${NAMESPACE}
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
name: cert-manager-operator
10+
policyTypes:
11+
- Egress
12+
egress:
13+
- ports:
14+
- protocol: TCP
15+
port: 6443
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: operator-allow-ingress-to-metrics
5+
namespace: ${NAMESPACE}
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
name: cert-manager-operator
10+
policyTypes:
11+
- Ingress
12+
ingress:
13+
- ports:
14+
- protocol: TCP
15+
port: 8443
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: operator-deny-all-traffic
5+
namespace: ${NAMESPACE}
6+
spec:
7+
podSelector:
8+
matchLabels:
9+
name: cert-manager-operator
10+
policyTypes:
11+
- Ingress
12+
- Egress

pkg/controller/deployment/cert_manager_controller_set.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ type CertManagerControllerSet struct {
2121
certManagerWebhookDeploymentController factory.Controller
2222
certManagerCAInjectorStaticResourcesController factory.Controller
2323
certManagerCAInjectorDeploymentController factory.Controller
24+
certManagerOperatorStaticResourcesController factory.Controller
2425
}
2526

2627
func NewCertManagerControllerSet(
@@ -44,6 +45,7 @@ func NewCertManagerControllerSet(
4445
certManagerWebhookDeploymentController: NewCertManagerWebhookDeploymentController(operatorClient, certManagerOperatorInformers, infraInformers, kubeClient, kubeInformersForTargetNamespace, eventRecorder, targetVersion, versionRecorder, trustedCAConfigmapName, cloudCredentialsSecretName),
4546
certManagerCAInjectorStaticResourcesController: NewCertManagerCAInjectorStaticResourcesController(operatorClient, kubeClientContainer, kubeInformersForNamespaces, eventRecorder),
4647
certManagerCAInjectorDeploymentController: NewCertManagerCAInjectorDeploymentController(operatorClient, certManagerOperatorInformers, infraInformers, kubeClient, kubeInformersForTargetNamespace, eventRecorder, targetVersion, versionRecorder, trustedCAConfigmapName, cloudCredentialsSecretName),
48+
certManagerOperatorStaticResourcesController: NewCertManagerOperatorStaticResourcesController(operatorClient, kubeClientContainer, kubeInformersForNamespaces, eventRecorder),
4749
}
4850
}
4951

@@ -55,5 +57,6 @@ func (c *CertManagerControllerSet) ToArray() []factory.Controller {
5557
c.certManagerWebhookDeploymentController,
5658
c.certManagerCAInjectorStaticResourcesController,
5759
c.certManagerCAInjectorDeploymentController,
60+
c.certManagerOperatorStaticResourcesController,
5861
}
5962
}
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
package deployment
2+
3+
import (
4+
"bytes"
5+
"github.com/openshift/cert-manager-operator/pkg/operator/operatorclient"
6+
"github.com/openshift/library-go/pkg/controller/factory"
7+
"github.com/openshift/library-go/pkg/operator/events"
8+
"github.com/openshift/library-go/pkg/operator/resource/resourceapply"
9+
"github.com/openshift/library-go/pkg/operator/staticresourcecontroller"
10+
"github.com/openshift/library-go/pkg/operator/v1helpers"
11+
12+
"github.com/openshift/cert-manager-operator/pkg/operator/assets"
13+
)
14+
15+
const (
16+
certManagerOperatorStaticResourcesControllerName = operatorName + "-operator-static-resources-"
17+
namespaceKey = "${NAMESPACE}"
18+
)
19+
20+
var (
21+
certManagerOperatorAssetFiles = []string{
22+
"cert-manager-deployment/network-policy/operator-allow-egress-to-api-server.yaml",
23+
"cert-manager-deployment/network-policy/operator-allow-ingress-to-metrics.yaml",
24+
"cert-manager-deployment/network-policy/operator-deny-all-pod-selector.yaml",
25+
}
26+
)
27+
28+
func NewCertManagerOperatorStaticResourcesController(operatorClient v1helpers.OperatorClient,
29+
kubeClientContainer *resourceapply.ClientHolder,
30+
kubeInformersForNamespaces v1helpers.KubeInformersForNamespaces,
31+
eventsRecorder events.Recorder,
32+
) factory.Controller {
33+
return staticresourcecontroller.NewStaticResourceController(
34+
certManagerOperatorStaticResourcesControllerName,
35+
replaceNamespaceFunc(operatorclient.OperatorNamespace),
36+
certManagerOperatorAssetFiles,
37+
kubeClientContainer,
38+
operatorClient,
39+
eventsRecorder,
40+
).AddKubeInformers(kubeInformersForNamespaces)
41+
}
42+
43+
func replaceNamespaceFunc(namespace string) resourceapply.AssetFunc {
44+
return func(name string) ([]byte, error) {
45+
content, err := assets.Asset(name)
46+
if err != nil {
47+
panic(err)
48+
}
49+
return bytes.ReplaceAll(content, []byte(namespaceKey), []byte(namespace)), nil
50+
}
51+
}

pkg/operator/assets/bindata.go

Lines changed: 103 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
package operatorclient
22

33
const (
4-
TargetNamespace = "cert-manager"
4+
TargetNamespace = "cert-manager"
5+
)
6+
7+
var (
58
OperatorNamespace = "cert-manager-operator"
69
)

pkg/operator/starter.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,10 +71,13 @@ func RunOperator(ctx context.Context, cc *controllercmd.ControllerContext) error
7171
versionRecorder := status.NewVersionGetter()
7272
versionRecorder.SetVersion("operator", status.VersionForOperatorFromEnv())
7373

74+
operatorclient.OperatorNamespace = cc.OperatorNamespace
75+
7476
kubeInformersForNamespaces := v1helpers.NewKubeInformersForNamespaces(kubeClient,
7577
"",
7678
"kube-system",
7779
operatorclient.TargetNamespace,
80+
operatorclient.OperatorNamespace,
7881
)
7982

8083
configClient, err := configv1client.NewForConfig(cc.KubeConfig)

0 commit comments

Comments
 (0)