Kuadrant / Kuadrant/architecture
RFC: Default NetworkPolicies for Kuadrant Components
- Dominant language
- No language data
- Stars
- 3
- Forks
- 16
- Avg merge
- 7d 11h
- Merged PRs (30d)
- 2
Description
Ship default-deny NetworkPolicies for all Kuadrant operators and operands. Operators deny all ingress except metrics/health. Authorino and Limitador additionally allow gRPC ingress from gateway namespaces configured via a new `spec.allowedNamespaces` CRD field. kuadrant-operator auto-derives gateway namespaces from its topology.
Contributor guide
Research direction
Start by reviewing this RFC's requirements for Kuadrant operators and operands, including the default-deny rules and the proposed spec.allowedNamespaces field. Trace how kuadrant-operator derives gateway namespaces from topology and identify the affected components. Done means the stated ingress exceptions and gateway access behavior are defined for all listed components.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- grpc, kubernetes
- Domain
- infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100