146 lines
3.6 KiB
YAML
146 lines
3.6 KiB
YAML
|
|
{{- if .Values.networkPolicies.enabled }}
|
||
|
|
apiVersion: networking.k8s.io/v1
|
||
|
|
kind: NetworkPolicy
|
||
|
|
metadata:
|
||
|
|
name: dashboard-web-netpol
|
||
|
|
namespace: {{ .Values.namespace }}
|
||
|
|
labels:
|
||
|
|
{{- include "osint-dashboard.labels" . | nindent 4 }}
|
||
|
|
app.kubernetes.io/component: security
|
||
|
|
spec:
|
||
|
|
podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: web
|
||
|
|
policyTypes:
|
||
|
|
- Ingress
|
||
|
|
- Egress
|
||
|
|
ingress:
|
||
|
|
# Allow from ingress controller / Gateway API
|
||
|
|
- from:
|
||
|
|
- namespaceSelector:
|
||
|
|
matchLabels:
|
||
|
|
kubernetes.io/metadata.name: ingress-nginx
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 3000
|
||
|
|
egress:
|
||
|
|
# Allow DNS
|
||
|
|
- to:
|
||
|
|
- namespaceSelector: {}
|
||
|
|
podSelector:
|
||
|
|
matchLabels:
|
||
|
|
k8s-app: kube-dns
|
||
|
|
ports:
|
||
|
|
- protocol: UDP
|
||
|
|
port: 53
|
||
|
|
- protocol: TCP
|
||
|
|
port: 53
|
||
|
|
# Allow to API
|
||
|
|
- to:
|
||
|
|
- podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: api
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 4000
|
||
|
|
# Allow to external APIs (GDelt, satellite providers)
|
||
|
|
- to:
|
||
|
|
- ipBlock:
|
||
|
|
cidr: 0.0.0.0/0
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 443
|
||
|
|
---
|
||
|
|
apiVersion: networking.k8s.io/v1
|
||
|
|
kind: NetworkPolicy
|
||
|
|
metadata:
|
||
|
|
name: dashboard-api-netpol
|
||
|
|
namespace: {{ .Values.namespace }}
|
||
|
|
labels:
|
||
|
|
{{- include "osint-dashboard.labels" . | nindent 4 }}
|
||
|
|
app.kubernetes.io/component: security
|
||
|
|
spec:
|
||
|
|
podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: api
|
||
|
|
policyTypes:
|
||
|
|
- Ingress
|
||
|
|
- Egress
|
||
|
|
ingress:
|
||
|
|
# Allow from web frontend
|
||
|
|
- from:
|
||
|
|
- podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: web
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 4000
|
||
|
|
# Allow from ingress controller / Gateway API
|
||
|
|
- from:
|
||
|
|
- namespaceSelector:
|
||
|
|
matchLabels:
|
||
|
|
kubernetes.io/metadata.name: ingress-nginx
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 4000
|
||
|
|
egress:
|
||
|
|
# Allow DNS
|
||
|
|
- to:
|
||
|
|
- namespaceSelector: {}
|
||
|
|
podSelector:
|
||
|
|
matchLabels:
|
||
|
|
k8s-app: kube-dns
|
||
|
|
ports:
|
||
|
|
- protocol: UDP
|
||
|
|
port: 53
|
||
|
|
- protocol: TCP
|
||
|
|
port: 53
|
||
|
|
# Allow to PostgreSQL
|
||
|
|
- to:
|
||
|
|
- podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: database
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 5432
|
||
|
|
# Allow to Redis
|
||
|
|
- to:
|
||
|
|
- podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: cache
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: {{ .Values.redis.ports.redis }}
|
||
|
|
# Allow to NATS
|
||
|
|
- to:
|
||
|
|
- podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: messaging
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: {{ .Values.nats.ports.client }}
|
||
|
|
# Allow to MinIO
|
||
|
|
- to:
|
||
|
|
- podSelector:
|
||
|
|
matchLabels:
|
||
|
|
app.kubernetes.io/name: osint-dashboard
|
||
|
|
app.kubernetes.io/component: object-storage
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: {{ .Values.minio.ports.api }}
|
||
|
|
# Allow to external APIs (GDelt, etc.)
|
||
|
|
- to:
|
||
|
|
- ipBlock:
|
||
|
|
cidr: 0.0.0.0/0
|
||
|
|
ports:
|
||
|
|
- protocol: TCP
|
||
|
|
port: 443
|
||
|
|
{{- end }}
|