diff --git a/thelounge/kustomization.yaml b/thelounge/kustomization.yaml index 143db19..f129176 100644 --- a/thelounge/kustomization.yaml +++ b/thelounge/kustomization.yaml @@ -1,7 +1,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - networkpolicy.yaml - statefulset.yaml - service.yaml - httproute.yaml diff --git a/thelounge/networkpolicy.yaml b/thelounge/networkpolicy.yaml deleted file mode 100644 index 547c368..0000000 --- a/thelounge/networkpolicy.yaml +++ /dev/null @@ -1,46 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: thelounge -spec: - podSelector: - matchLabels: - app.kubernetes.io/name: thelounge - policyTypes: - - Ingress - - Egress - - ingress: - ### Allow all ingress traffic (web app needs external access via gateway) - - {} - ### - egress: - ### Allow DNS resolution - - to: - - namespaceSelector: - matchLabels: - kubernetes.io/metadata.name: kube-system - podSelector: - matchLabels: - k8s-app: kube-dns - ports: - - protocol: UDP - port: 53 - - protocol: TCP - port: 53 - ### - ### Allow intra-namespace communication - - to: - - namespaceSelector: - matchLabels: - kubernetes.io/metadata.name: irc - ### - ### Allow outbound to the world - - to: - - ipBlock: - cidr: 0.0.0.0/0 - except: - - 10.0.0.0/8 - - 172.16.0.0/12 - - 192.168.0.0/16 - ### diff --git a/znc/kustomization.yaml b/znc/kustomization.yaml index de03cc5..19751c8 100644 --- a/znc/kustomization.yaml +++ b/znc/kustomization.yaml @@ -1,6 +1,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - networkpolicy.yaml - statefulset.yaml - service.yaml diff --git a/znc/networkpolicy.yaml b/znc/networkpolicy.yaml deleted file mode 100644 index f6a6a90..0000000 --- a/znc/networkpolicy.yaml +++ /dev/null @@ -1,46 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: znc -spec: - podSelector: - matchLabels: - app.kubernetes.io/name: znc - policyTypes: - - Ingress - - Egress - - ingress: - ### Allow all ingress traffic (IRC bouncer needs external connections) - - {} - ### - egress: - ### Allow DNS resolution - - to: - - namespaceSelector: - matchLabels: - kubernetes.io/metadata.name: kube-system - podSelector: - matchLabels: - k8s-app: kube-dns - ports: - - protocol: UDP - port: 53 - - protocol: TCP - port: 53 - ### - ### Allow intra-namespace communication - - to: - - namespaceSelector: - matchLabels: - kubernetes.io/metadata.name: irc - ### - ### Allow outbound to the world - - to: - - ipBlock: - cidr: 0.0.0.0/0 - except: - - 10.0.0.0/8 - - 172.16.0.0/12 - - 192.168.0.0/16 - ###