Auto-Deploy on Push / verify-and-notify (push) Canceled after 0s
Ingress-only default-deny (egress untouched) plus explicit allows: Traefik (kube-system) + MAS (matrix ns) -> authentik-server on 80/443, and Traefik -> cert-manager's ACME HTTP-01 solver pods on 8089. authentik-postgresql already has its own Bitnami-chart-managed policy, left alone. Part of issue #10.
65 lines
1.8 KiB
YAML
65 lines
1.8 KiB
YAML
# Default-deny ingress for the authentik namespace, with explicit allow rules for the
|
|
# traffic paths that actually need to reach in: Traefik (kube-system) for the public
|
|
# auth.axion1337.chat endpoint and ACME HTTP-01 challenges, and MAS (matrix namespace)
|
|
# for upstream OIDC calls. Egress is intentionally untouched (federation-equivalent
|
|
# outbound calls like SMTP aren't restricted here).
|
|
#
|
|
# Note: authentik-postgresql already has its own NetworkPolicy from the Bitnami
|
|
# postgresql subchart (port 5432, no source restriction) - left alone, not duplicated,
|
|
# since it would get reset on the next Helm upgrade anyway.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: default-deny-ingress
|
|
namespace: authentik
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes:
|
|
- Ingress
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-ingress-authentik-server
|
|
namespace: authentik
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: authentik
|
|
app.kubernetes.io/component: server
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: matrix
|
|
ports:
|
|
- protocol: TCP
|
|
port: 80
|
|
- protocol: TCP
|
|
port: 443
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-ingress-acme-solver
|
|
namespace: authentik
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
acme.cert-manager.io/http01-solver: "true"
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8089
|