networkpolicies
networkPolicy objects to be generated by the chart. Additional networkPolicies can be added by adding a dictionary key similar to the ‘main’ networkPolicy.
object
Keys are identifiers for networkpolicies instances.
networkpolicies: main: enabled: true # ... configuration
secondary: enabled: true # ... configurationExamples
Section titled “Examples”networkpolicies: ciliumClusterwide: type: ciliumClusterwide nodeSelector: matchLabels: kubernetes.io/os: linux ingress: - fromEntities: - clusterType Variants
Section titled “Type Variants”CiliumNetworkPolicy implementation to render.
| Property | Type | Required | Default | Description |
|---|---|---|---|---|
annotations | object / null | No | - | Annotations to set on the item. |
controller | string | No | - | Controller this CiliumNetworkPolicy should target. |
description | string | No | - | Human-readable description of the policy. |
egress | array | No | - | Cilium egress rules. See https://docs.cilium.io/en/stable… |
egressDeny | array | No | - | Cilium egress deny rules. Deny rules take precedence over… |
enableDefaultDeny | object | No | - | Configure whether the selected endpoints enter default-de… |
enabled | boolean | No | true | Set to false to disable the CiliumNetworkPolicy. |
endpointSelector | object | No | - | Custom endpointSelector for the CiliumNetworkPolicy. Take… |
extraSelectorLabels | object | No | - | Additional match labels to add to the endpoint selector. … |
forceRename | string | No | - | Override the default resource name. Mutually exclusive wi… |
ingress | array | Yes | - | Cilium ingress rules. See https://docs.cilium.io/en/stabl… |
ingressDeny | array | No | - | Cilium ingress deny rules. Deny rules take precedence ove… |
labels | object / null | No | - | Labels to set on the item. |
log | string | No | - | Free-form value included in Hubble flows matching this po… |
nodeSelector | object | No | - | Node selector for a CiliumClusterwideNetworkPolicy. |
prefix | string | No | “ | Prefix to prepend to the resource name. Mutually exclusiv… |
suffix | string | No | - | Suffix to append to the resource name. Defaults to the re… |
Cluster-scoped CiliumClusterwideNetworkPolicy implementation to render. The resource is rendered without metadata.namespace.
networkpolicies: ciliumClusterwide: type: ciliumClusterwide nodeSelector: matchLabels: kubernetes.io/os: linux ingress: - fromEntities: - cluster| Property | Type | Required | Default | Description |
|---|---|---|---|---|
annotations | object / null | No | - | Annotations to set on the item. |
controller | string | No | - | Controller this CiliumNetworkPolicy should target. |
description | string | No | - | Human-readable description of the policy. |
egress | array | No | - | Cilium egress rules. See https://docs.cilium.io/en/stable… |
egressDeny | array | No | - | Cilium egress deny rules. Deny rules take precedence over… |
enableDefaultDeny | object | No | - | Configure whether the selected endpoints enter default-de… |
enabled | boolean | No | true | Set to false to disable the CiliumNetworkPolicy. |
endpointSelector | object | No | - | Custom endpointSelector for the CiliumNetworkPolicy. Take… |
extraSelectorLabels | object | No | - | Additional match labels to add to the endpoint selector. … |
forceRename | string | No | - | Override the default resource name. Mutually exclusive wi… |
ingress | array | Yes | - | Cilium ingress rules. See https://docs.cilium.io/en/stabl… |
ingressDeny | array | No | - | Cilium ingress deny rules. Deny rules take precedence ove… |
labels | object / null | No | - | Labels to set on the item. |
log | string | No | - | Free-form value included in Hubble flows matching this po… |
nodeSelector | object | No | - | Node selector for a CiliumClusterwideNetworkPolicy. |
prefix | string | No | “ | Prefix to prepend to the resource name. Mutually exclusiv… |
suffix | string | No | - | Suffix to append to the resource name. Defaults to the re… |
Instance Properties
Section titled “Instance Properties”Common properties:
| Property | Type | Required | Default | Description |
|---|---|---|---|---|
annotations | object / null | No | - | Annotations to set on the item. |
controller | string | No | - | Controller this NetworkPolicy should target. |
enabled | boolean | No | true | Set to false to disable the NetworkPolicy. |
extraSelectorLabels | object | No | - | Additional match labels to add to the pod selector. These… |
forceRename | string | No | - | Override the default resource name. Mutually exclusive wi… |
labels | object / null | No | - | Labels to set on the item. |
podSelector | any | No | - | Custom podSelector for the NetworkPolicy. Takes precedenc… |
policyTypes | array | Yes | - | Policy types for the NetworkPolicy. |
prefix | string | No | “ | Prefix to prepend to the resource name. Mutually exclusiv… |
rules | object | Yes | - | Ingress and egress rules for the NetworkPolicy. See https… |
suffix | string | No | - | Suffix to append to the resource name. Defaults to the re… |
type | string | No | - | Resource implementation to render. Set type to native, ci… |
Property Details
Section titled “Property Details”extraSelectorLabels
Section titled “extraSelectorLabels”Additional match labels to add to the pod selector. These are merged with labels derived from the controller identifier.
forceRename
Section titled “forceRename”Override the default resource name. Mutually exclusive with prefix and suffix.
podSelector
Section titled “podSelector”Custom podSelector for the NetworkPolicy. Takes precedence over targeting a controller via the controller identifier.
prefix
Section titled “prefix”Prefix to prepend to the resource name. Mutually exclusive with forceRename.
suffix
Section titled “suffix”Suffix to append to the resource name. Defaults to the resource identifier if there are multiple items, otherwise empty. Mutually exclusive with forceRename.
Resource implementation to render. Set type to native, cilium, or ciliumClusterwide.
Allowed values: native, cilium, ciliumClusterwide