Exploring cilium netpolicies.

This commit is contained in:
Joseph Hanson 2024-01-08 13:26:25 -06:00
parent aae23883b7
commit f2f23345ef

View file

@ -36,6 +36,13 @@ spec:
enabled: true enabled: true
ipam: ipam:
mode: kubernetes mode: kubernetes
policyEnforcementMode: always # enforce network policies
policyAuditMode: true # do not block traffic
hostFirewall:
enabled: true # enable host policies
extraConfig:
allow-localhost: policy # enable policies for localhost
kubeProxyReplacement: true kubeProxyReplacement: true
securityContext: securityContext:
capabilities: capabilities: