diff --git a/infrastructure/longhorn/kustomization.yaml b/infrastructure/longhorn/kustomization.yaml index 844330355ef22cb4cca4c7ea524224a5c6454943..6224fb6ce85868d877677af638db6ee68d26ca03 100644 --- a/infrastructure/longhorn/kustomization.yaml +++ b/infrastructure/longhorn/kustomization.yaml @@ -5,3 +5,12 @@ resources: - namespace.yaml - repository.yaml - release.yaml + # Add network policies + - https://git.shivering-isles.com/github-mirror/longhorn/longhorn/-/raw/v1.2.3/examples/network-policy/manager-network-policy.yaml + - https://git.shivering-isles.com/github-mirror/longhorn/longhorn/-/raw/v1.2.3/examples/network-policy/instance-manager-networking.yaml + - https://git.shivering-isles.com/github-mirror/longhorn/longhorn/-/raw/v1.2.3/examples/network-policy/backing-image-manager-network-policy.yaml + - https://git.shivering-isles.com/github-mirror/longhorn/longhorn/-/raw/v1.2.3/examples/network-policy/backing-image-data-source-network-policy.yaml + - ../../../shared/networkpolicies/allow-from-ingress.yaml +patchesStrategicMerge: + - networkpolicy.yaml + diff --git a/infrastructure/longhorn/networkpolicy.yaml b/infrastructure/longhorn/networkpolicy.yaml new file mode 100644 index 0000000000000000000000000000000000000000..7bccdebf8da21001a95a6babf3754f33d4441e66 --- /dev/null +++ b/infrastructure/longhorn/networkpolicy.yaml @@ -0,0 +1,8 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: allow-ingress +spec: + podSelector: + matchLabels: + app: longhorn-ui