# Default-deny ingress for the authentik namespace, with explicit allow rules for the # traffic paths that actually need to reach in: Traefik (kube-system) for the public # auth.axion1337.chat endpoint and ACME HTTP-01 challenges, and MAS (matrix namespace) # for upstream OIDC calls. Egress is intentionally untouched (federation-equivalent # outbound calls like SMTP aren't restricted here). # # authentik-postgresql: the Bitnami postgresql subchart's own generated NetworkPolicy # restricted the port (5432) but not the source - any pod in any namespace could reach # it (issue #37). Disabled via postgresql.primary.networkPolicy.enabled: false in # authentik.yaml and replaced below with a policy scoped to authentik-server/-worker. apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: default-deny-ingress namespace: authentik spec: podSelector: {} policyTypes: - Ingress --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-ingress-authentik-server namespace: authentik spec: podSelector: matchLabels: app.kubernetes.io/name: authentik app.kubernetes.io/component: server policyTypes: - Ingress ingress: - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: kube-system - namespaceSelector: matchLabels: kubernetes.io/metadata.name: matrix ports: # NetworkPolicy matches the pod's actual container port, not the Service's # external port - the authentik-server Service maps 80->9000, 443->9443. - protocol: TCP port: 9000 - protocol: TCP port: 9443 --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-ingress-authentik-postgresql namespace: authentik spec: podSelector: matchLabels: app.kubernetes.io/name: postgresql app.kubernetes.io/component: primary policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: app.kubernetes.io/name: authentik app.kubernetes.io/component: server - podSelector: matchLabels: app.kubernetes.io/name: authentik app.kubernetes.io/component: worker - podSelector: matchLabels: app.kubernetes.io/name: authentik-backup ports: - protocol: TCP port: 5432 --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-ingress-acme-solver namespace: authentik spec: podSelector: matchLabels: acme.cert-manager.io/http01-solver: "true" policyTypes: - Ingress ingress: - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: kube-system ports: - protocol: TCP port: 8089