Skip to content

network-policies-app: clusterwide default-deny, opt-out label, grandfathering #4340

Description

@weatherhog

Part of #4338.

Extend giantswarm/network-policies-app (target: v1.0.0):

  • New CCNP template default-deny-all-namespaces + clusterwide allow-dns, per spike results
  • Values: denyByDefault.clusterWide.{enabled, optOutLabel, grandfatherExistingNamespaces} (keep existing denyByDefault.namespaces behavior untouched)
  • One-shot Helm hook Job + RBAC: on first enablement, label all pre-existing non-GS namespaces policy.giantswarm.io/default-deny=false
  • Tests (helm-unittest/chainsaw) + README covering opt-out and exception workflow

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Inbox 📥

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions