fix(networkpolicy): allow all egress for API server access#3755
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3755 +/- ##
==========================================
- Coverage 25.49% 25.47% -0.03%
==========================================
Files 449 449
Lines 23370 23363 -7
==========================================
- Hits 5959 5952 -7
Misses 16725 16725
Partials 686 686
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
ef6c3df to
db76d53
Compare
|
@khrm can you update. the doc under docs/networkpolicy.md |
db76d53 to
7df4cbf
Compare
|
@khrm can you update the doc please to reflect the PR ? |
NetworkPolicy cannot select host-network endpoints and the API server port is configurable, so allow unrestricted egress. Remove APIServerPort from PlatformParams. Admin network policy could improve this later but would break third-party SDNs. Signed-off-by: Khurram Baig <kbaig@redhat.com> Assisted-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
7df4cbf to
23092ed
Compare
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: jkhelil The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
khrm
left a comment
There was a problem hiding this comment.
/assign @pramodbindal
|
/;gtm |
|
/lgtm |
NetworkPolicy cannot select host-network endpoints, and the API server port is configurable (SDN sometime have different port), so allow unrestricted egress. Remove APIServerPort from PlatformParams. Admin network policy could improve this later but would break third-party SDNs.
Assisted-by: Claude Opus 4.6 (1M context) noreply@anthropic.com
Changes
Submitter Checklist
These are the criteria that every PR should meet, please check them off as you
review them:
make test lintbefore submitting a PRSee the contribution guide for more details.
Release Notes