Skip to content

Commit 717e871

Browse files
author
Per G. da Silva
committed
restrict kube-apiserver and dns traffic
Signed-off-by: Per G. da Silva <[email protected]>
1 parent 90300eb commit 717e871

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

deploy/chart/values.yaml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -85,10 +85,24 @@ networkPolicy:
8585
port: 53
8686
- protocol: UDP
8787
port: 53
88+
to:
89+
- namespaceSelector:
90+
matchLabels:
91+
kubernetes.io/metadata.name: kube-system
92+
podSelector:
93+
matchLabels:
94+
k8s-app: kube-dns
8895
kubeAPIServer:
8996
ports:
9097
- protocol: TCP
9198
port: 6443
99+
to:
100+
- namespaceSelector:
101+
matchLabels:
102+
kubernetes.io/metadata.name: kube-system
103+
podSelector:
104+
matchLabels:
105+
component: kube-apiserver
92106
metrics:
93107
ports:
94108
- protocol: TCP

0 commit comments

Comments
 (0)