Skip to content

Commit e8a7abd

Browse files
committed
OPRUN-3895: Namespace wide default deny for ingress/egress
1 parent 10314ff commit e8a7abd

File tree

2 files changed

+11
-0
lines changed

2 files changed

+11
-0
lines changed

config/base/common/kustomization.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
22
kind: Kustomization
33
resources:
44
- namespace.yaml
5+
- network_policy.yaml
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
apiVersion: networking.k8s.io/v1
2+
kind: NetworkPolicy
3+
metadata:
4+
name: default-deny-all-traffic
5+
namespace: system
6+
spec:
7+
podSelector: { }
8+
policyTypes:
9+
- Ingress
10+
- Egress

0 commit comments

Comments
 (0)