feat(operator): secure system server workloads
This commit is contained in:
10 files changed
+191
-59
No files matched your search
@@ -77,12 +77,12 @@ type Params struct {
|
||||
// BuildNamespace is where image-build Jobs run under the weak felis-build SA,
|
||||
// with the egress-locked NetworkPolicy.
|
||||
BuildNamespace string
|
||||
// VelocityCIDRs are the off-cluster Velocity proxy source addresses permitted
|
||||
// to reach server game ports (25565). Velocity runs on a separate macvlan host
|
||||
// (spec §20), NOT a Kubernetes node, so this is an ipBlock allowlist and can
|
||||
// never be a podSelector. It has NO default: an empty list renders a
|
||||
// fail-closed game policy that admits no one (never an accidental allow-all),
|
||||
// and the `felis manifests` generator refuses to emit a bundle without it.
|
||||
// VelocityCIDRs are the Velocity proxy source addresses permitted to reach
|
||||
// server game ports (25565) as ipBlock peers. The bootstrap proxy runs on the
|
||||
// k3s node; other deployments may use a separate host. Kubernetes always permits
|
||||
// resident-node traffic independently of NetworkPolicy, so this list constrains
|
||||
// non-node sources. It has NO default, and the `felis manifests` generator
|
||||
// refuses to emit a bundle without an explicit proxy placement.
|
||||
VelocityCIDRs []string
|
||||
// RegistryNamespace / RegistryPort locate the in-cluster image registry the
|
||||
// build egress policy may reach (spec §16). RegistryNamespace defaults to the
|
||||
|
||||
@@ -95,16 +95,15 @@ func allowRConFromControlPlane(p Params) *networkingv1.NetworkPolicy {
|
||||
return np
|
||||
}
|
||||
|
||||
// allowGameFromVelocity opens 25565 on server pods to the off-cluster Velocity
|
||||
// proxy host(s) by ipBlock. Velocity is NOT a K8s pod (spec §20: it runs on a
|
||||
// separate macvlan host), so the peer can only be an ipBlock — never a
|
||||
// podSelector.
|
||||
// allowGameFromVelocity opens 25565 on server pods to Velocity proxy host(s) by
|
||||
// ipBlock. The supported proxy runs outside the pod network (on the k3s node or a
|
||||
// separate host), so the peer is an ipBlock rather than a podSelector. Kubernetes
|
||||
// always permits resident-node traffic; these rules constrain other sources.
|
||||
//
|
||||
// Fail-closed: with no VelocityCIDRs the policy carries NO ingress rule (deny all
|
||||
// game ingress), never an empty-From rule, which K8s would read as allow-all. The
|
||||
// `felis manifests` generator additionally refuses an empty velocity list, so the
|
||||
// rendered bundle is always either correctly scoped or absent — never accidentally
|
||||
// open.
|
||||
// With no VelocityCIDRs the policy carries NO ingress rule, never an empty-From
|
||||
// rule (which K8s would read as allow-all). That denies non-node game traffic;
|
||||
// resident-node traffic remains outside NetworkPolicy's blocking capability. The
|
||||
// manifest generator still refuses an empty list so remote proxies fail loudly.
|
||||
func allowGameFromVelocity(p Params) *networkingv1.NetworkPolicy {
|
||||
tcp := corev1.ProtocolTCP
|
||||
port := intstr.FromInt32(gamePort)
|
||||
|
||||
Reference in new issue
Block a user