Auto-Deploy on Push / verify-and-notify (push) Canceled after 0s
Caused a live 502 immediately after deploy: the rule allowed 80/443 (the Service's external ports), but NetworkPolicy filters on the pod's actual container port after kube-proxy's DNAT - authentik-server's Service maps 80->9000 and 443->9443. Confirmed root cause by suspending Flux reconciliation (it was silently re-applying my manual test deletions) and testing with the policies truly absent.
67 lines
2.0 KiB
YAML
67 lines
2.0 KiB
YAML
# Default-deny ingress for the authentik namespace, with explicit allow rules for the
|
|
# traffic paths that actually need to reach in: Traefik (kube-system) for the public
|
|
# auth.axion1337.chat endpoint and ACME HTTP-01 challenges, and MAS (matrix namespace)
|
|
# for upstream OIDC calls. Egress is intentionally untouched (federation-equivalent
|
|
# outbound calls like SMTP aren't restricted here).
|
|
#
|
|
# Note: authentik-postgresql already has its own NetworkPolicy from the Bitnami
|
|
# postgresql subchart (port 5432, no source restriction) - left alone, not duplicated,
|
|
# since it would get reset on the next Helm upgrade anyway.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: default-deny-ingress
|
|
namespace: authentik
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes:
|
|
- Ingress
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-ingress-authentik-server
|
|
namespace: authentik
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: authentik
|
|
app.kubernetes.io/component: server
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: matrix
|
|
ports:
|
|
# NetworkPolicy matches the pod's actual container port, not the Service's
|
|
# external port - the authentik-server Service maps 80->9000, 443->9443.
|
|
- protocol: TCP
|
|
port: 9000
|
|
- protocol: TCP
|
|
port: 9443
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-ingress-acme-solver
|
|
namespace: authentik
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
acme.cert-manager.io/http01-solver: "true"
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8089
|