feat(v1.0.3): NP egress HTTPS ouvert au node IP (hairpin) + allowEgressExtra
This commit is contained in:
@@ -63,17 +63,24 @@ spec:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
# Sortie HTTPS vers Internet (Let's Encrypt ACME, external APIs)
|
||||
# Sortie HTTPS vers Internet (Let's Encrypt ACME, external APIs, ingress hairpin)
|
||||
# Inclut le node IP lui-même pour résoudre les URLs publiques (ex: security.lions.dev)
|
||||
# qui reviennent vers ingress-nginx via hairpin NAT
|
||||
- to:
|
||||
- ipBlock:
|
||||
cidr: 0.0.0.0/0
|
||||
except:
|
||||
- 10.0.0.0/8
|
||||
- 172.16.0.0/12
|
||||
- 192.168.0.0/16
|
||||
ports:
|
||||
- port: 443
|
||||
protocol: TCP
|
||||
- port: 80
|
||||
protocol: TCP
|
||||
# Egress additionnels définis par l'app (pour accès cluster-internal)
|
||||
{{- range .Values.networkPolicy.allowEgressExtra }}
|
||||
- to:
|
||||
{{- toYaml .to | nindent 8 }}
|
||||
{{- with .ports }}
|
||||
ports:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
Reference in New Issue
Block a user