JG-mirror/Vaultwarden/Kubernetes/networkpolicy.yaml
2024-07-08 11:19:54 +01:00

35 lines
680 B
YAML

kind: NetworkPolicy
apiVersion: networking.k8s.io/v1
metadata:
name: allow-internet-only
namespace: vaultwarden
spec:
podSelector: {}
policyTypes:
- Egress
- Ingress
egress:
- to:
- ipBlock:
cidr: "0.0.0.0/0"
except:
- "10.0.0.0/8"
- "172.16.0.0/12"
- "192.168.0.0/16"
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: "kube-system"
- podSelector:
matchLabels:
k8s-app: "kube-dns"
ingress:
- from:
- ipBlock:
cidr: "10.0.0.0/8"
- from:
- ipBlock:
cidr: "172.16.0.0/12"
- from:
- ipBlock:
cidr: "192.168.0.0/16"