fix: NetworkPolicy egress complet (Postgres + Keycloak + Kafka si besoin)

This commit is contained in:
dahoud
2026-04-22 15:50:22 +00:00
parent 52306609f0
commit 51477f9e3d
2 changed files with 25 additions and 2 deletions

View File

@@ -14,5 +14,5 @@ sources:
- https://git.lions.dev/lionsdev/unionflow-client-quarkus-primefaces-freya-k1 - https://git.lions.dev/lionsdev/unionflow-client-quarkus-primefaces-freya-k1
dependencies: dependencies:
- name: lions-app - name: lions-app
version: "1.0.2" version: "1.0.3"
repository: "https://git.lions.dev/api/packages/lionsdev/helm" repository: "https://git.lions.dev/api/packages/lionsdev/helm"

View File

@@ -62,7 +62,30 @@ lions-app:
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k" nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
networkPolicy: networkPolicy:
enabled: false # TODO: re-enable après validation egress rules enabled: true
allowIngressFrom:
- namespaceSelector:
kubernetes.io/metadata.name: ingress-nginx
- namespaceSelector:
kubernetes.io/metadata.name: monitoring
allowEgressDNS: true
allowEgressKubeAPI: true
allowEgressTo:
- namespaceSelector:
kubernetes.io/metadata.name: postgresql
ports:
- port: 5432
protocol: TCP
- namespaceSelector:
kubernetes.io/metadata.name: keycloak
ports:
- port: 8080
protocol: TCP
- namespaceSelector:
kubernetes.io/metadata.name: kafka
ports:
- port: 9092
protocol: TCP
probes: probes:
liveness: liveness: