Kuadrant / Kuadrant/architecture

RFC: Default NetworkPolicies for Kuadrant Components

Open
#180 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
3
Forks
16
Avg merge
7d 11h
Merged PRs (30d)
2

Description

Ship default-deny NetworkPolicies for all Kuadrant operators and operands. Operators deny all ingress except metrics/health. Authorino and Limitador additionally allow gRPC ingress from gateway namespaces configured via a new `spec.allowedNamespaces` CRD field. kuadrant-operator auto-derives gateway namespaces from its topology.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing this RFC's requirements for Kuadrant operators and operands, including the default-deny rules and the proposed spec.allowedNamespaces field. Trace how kuadrant-operator derives gateway namespaces from topology and identify the affected components. Done means the stated ingress exceptions and gateway access behavior are defined for all listed components.

Written by the indexing model from the issue text.

Assessment

Tech stack
grpc, kubernetes
Domain
infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.