Skip to content
Snippets Groups Projects
Commit 5f0b680b authored by OZGCloud's avatar OZGCloud
Browse files

Merge pull request 'OZG-3880 network-policy add incoming from vorgangmanager,...

Merge pull request 'OZG-3880 network-policy add incoming from vorgangmanager, add additionalRules' (#97) from OZG-3880-add-incoming-network-policy-vorgang-manager into master

Reviewed-on: https://git.ozg-sh.de/ozgcloud-app/user-manager/pulls/97
parents c0297900 db301177
No related branches found
No related tags found
No related merge requests found
......@@ -37,9 +37,14 @@ spec:
ingress:
- ports:
- port: 8080
- ports:
- port: 9090
from:
- podSelector:
matchLabels:
component: vorgang-manager
{{- with (.Values.networkPolicy).additionalIngressConfig }}
- from:
{{ toYaml . | indent 8 }}
{{ toYaml . | indent 2 }}
{{- end }}
egress:
- to:
......@@ -66,5 +71,9 @@ spec:
protocol: UDP
- port: 5353
protocol: TCP
{{- with (.Values.networkPolicy).additionalEgressConfig }}
{{ toYaml . | indent 2 }}
{{- end }}
{{- end }}
......@@ -61,6 +61,12 @@ tests:
ingress:
- ports:
- port: 8080
- ports:
- port: 9090
from:
- podSelector:
matchLabels:
component: vorgang-manager
egress:
- to:
- podSelector:
......@@ -86,26 +92,43 @@ tests:
protocol: UDP
- port: 5353
protocol: TCP
- it: add ingress rule by values
set:
networkPolicy:
ssoPublicIp: 51.89.117.53/32
dnsServerNamespace: test-namespace-dns
additionalIngressConfig:
- from:
- podSelector:
matchLabels:
component: client2
asserts:
- equal:
- contains:
path: spec.ingress
value:
- ports:
- port: 8080
- from:
content:
from:
- podSelector:
matchLabels:
component: client2
- it: add egress rules by values
set:
networkPolicy:
ssoPublicIp: 51.89.117.53/32
dnsServerNamespace: test-dns-namespace
additionalEgressConfig:
- to:
- ipBlock:
cidr: 1.2.3.4/32
asserts:
- contains:
path: spec.egress
content:
to:
- ipBlock:
cidr: 1.2.3.4/32
- it: test network policy disabled
set:
networkPolicy:
......@@ -114,7 +137,7 @@ tests:
- hasDocuments:
count: 0
- it: test network policy unset should be disabled
- it: should generate network policies on disabled:false
set:
networkPolicy:
disabled: false
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment