Skip to content

Commit f76b6f7

Browse files
author
Shubha Narayanan
committed
Added newallow-from-kube-apiserver-operator policy
1 parent 78f4a3f commit f76b6f7

File tree

2 files changed

+40
-0
lines changed

2 files changed

+40
-0
lines changed

modules/nw-networkpolicy-multitenant-isolation.adoc

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,31 @@ spec:
9393
EOF
9494
----
9595

96+
.. A policy named `allow-from-kube-apiserver-operator`:
97+
+
98+
[source,terminal]
99+
----
100+
$ cat << EOF| oc create -f -
101+
apiVersion: networking.k8s.io/v1
102+
kind: NetworkPolicy
103+
metadata:
104+
name: allow-from-kube-apiserver-operator
105+
spec:
106+
ingress:
107+
- from:
108+
- namespaceSelector:
109+
matchLabels:
110+
kubernetes.io/metadata.name: openshift-kube-apiserver-operator
111+
podSelector:
112+
matchLabels:
113+
app: kube-apiserver-operator
114+
policyTypes:
115+
- Ingress
116+
EOF
117+
----
118+
+
119+
For more details, see link:https://access.redhat.com/solutions/6964520[New `kube-apiserver-operator` webhook controller validating health of webhook].
120+
96121
. Optional: To confirm that the network policies exist in your current project, enter the following command:
97122
+
98123
[source,terminal]

modules/nw-networkpolicy-project-defaults.adoc

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,21 @@ objects:
5959
podSelector: {}
6060
policyTypes:
6161
- Ingress
62+
- apiVersion: networking.k8s.io/v1
63+
kind: NetworkPolicy
64+
metadata:
65+
name: allow-from-kube-apiserver-operator
66+
spec:
67+
ingress:
68+
- from:
69+
- namespaceSelector:
70+
matchLabels:
71+
kubernetes.io/metadata.name: openshift-kube-apiserver-operator
72+
podSelector:
73+
matchLabels:
74+
app: kube-apiserver-operator
75+
policyTypes:
76+
- Ingress
6277
...
6378
----
6479

0 commit comments

Comments
 (0)