1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-09 09:26:54 +00:00
kyverno/samples/best_practices/require_default_network_policy.yaml

28 lines
637 B
YAML
Raw Normal View History

apiVersion: kyverno.io/v1alpha1
kind: ClusterPolicy
metadata:
name: defaultgeneratenetworkpolicy
spec:
rules:
- name: "default-networkpolicy"
match:
resources:
kinds:
- Namespace
2019-10-09 23:46:18 -07:00
name: "*"
generate:
kind: NetworkPolicy
name: defaultnetworkpolicy
data:
spec:
# select all pods in the namespace
podSelector: {}
policyTypes:
- Ingress
- Egress
# allow all ingress traffic from pods within this namespace
ingress:
- {}
# allow all egress traffic
egress:
- {}