549 lines
12 KiB
YAML
549 lines
12 KiB
YAML
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-dns
|
|
namespace: observability
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes:
|
|
- Egress
|
|
egress:
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
podSelector:
|
|
matchLabels:
|
|
k8s-app: kube-dns
|
|
ports:
|
|
- protocol: UDP
|
|
port: 53
|
|
- protocol: TCP
|
|
port: 53
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-kubernetes-api
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- kube-prometheus-stack-prometheus-operator
|
|
- kube-state-metrics
|
|
- prometheus
|
|
policyTypes:
|
|
- Egress
|
|
egress:
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 10.43.0.1/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 443
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 192.168.0.107/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 6443
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-prometheus-egress
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
policyTypes:
|
|
- Egress
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: kube-prometheus-stack-prometheus-operator
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8080
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: kube-state-metrics
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8080
|
|
- protocol: TCP
|
|
port: 8081
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9090
|
|
- protocol: TCP
|
|
port: 8080
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alertmanager
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9093
|
|
- protocol: TCP
|
|
port: 8080
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: loki
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: tempo
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3200
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3000
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus-blackbox-exporter
|
|
app.kubernetes.io/instance: blackbox-exporter
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9115
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: observability-agent
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alloy
|
|
ports:
|
|
- protocol: TCP
|
|
port: 12345
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: observability-agent
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus-node-exporter
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9100
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
podSelector:
|
|
matchLabels:
|
|
k8s-app: kube-dns
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9153
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 192.168.0.107/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 10250
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-prometheus-to-operator
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: kube-prometheus-stack-prometheus-operator
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8080
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-prometheus-to-ksm
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: kube-state-metrics
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8080
|
|
- protocol: TCP
|
|
port: 8081
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-prometheus-self
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9090
|
|
- protocol: TCP
|
|
port: 8080
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9090
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-alertmanager
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alertmanager
|
|
policyTypes:
|
|
- Ingress
|
|
- Egress
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9093
|
|
- protocol: TCP
|
|
port: 8080
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alertmanager
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9094
|
|
- protocol: UDP
|
|
port: 9094
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alertmanager
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9094
|
|
- protocol: UDP
|
|
port: 9094
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-loki
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: loki
|
|
policyTypes:
|
|
- Ingress
|
|
- Egress
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: observability-agent
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alloy
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: loki
|
|
ports:
|
|
- protocol: TCP
|
|
port: 7946
|
|
- protocol: UDP
|
|
port: 7946
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: loki
|
|
ports:
|
|
- protocol: TCP
|
|
port: 7946
|
|
- protocol: UDP
|
|
port: 7946
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-tempo
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: tempo
|
|
policyTypes:
|
|
- Ingress
|
|
- Egress
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3200
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3200
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: observability-agent
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: alloy
|
|
ports:
|
|
- protocol: TCP
|
|
port: 4317
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: tempo
|
|
ports:
|
|
- protocol: TCP
|
|
port: 7946
|
|
- protocol: UDP
|
|
port: 7946
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: tempo
|
|
ports:
|
|
- protocol: TCP
|
|
port: 7946
|
|
- protocol: UDP
|
|
port: 7946
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-aistor-egress
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
platform.hyeonworks.com/aistor-client: "true"
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- loki
|
|
- tempo
|
|
policyTypes:
|
|
- Egress
|
|
egress:
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 10.43.124.248/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 80
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: object-storage
|
|
podSelector:
|
|
matchLabels:
|
|
aistor.min.io/objectStore: minio-aistor
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9000
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-grafana-ingress
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: traefik
|
|
app.kubernetes.io/instance: traefik-kube-system
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3000
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3000
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus-blackbox-exporter
|
|
app.kubernetes.io/instance: blackbox-exporter
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3000
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-grafana-datasources
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
policyTypes:
|
|
- Egress
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: prometheus
|
|
ports:
|
|
- protocol: TCP
|
|
port: 9090
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: loki
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: tempo
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3200
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 192.168.0.107/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 443
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-allow-grafana-dashboard-api
|
|
namespace: observability
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
app.kubernetes.io/instance: grafana
|
|
policyTypes:
|
|
- Egress
|
|
egress:
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 10.43.0.1/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 443
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 192.168.0.107/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 6443
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: observability-default-deny
|
|
namespace: observability
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes:
|
|
- Ingress
|
|
- Egress
|