1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-06 16:06:56 +00:00
kyverno/examples/policy_generate_networkPolicy.yaml
2019-07-30 09:31:40 -07:00

32 lines
No EOL
755 B
YAML

apiVersion: kyverno.io/v1alpha1
kind: Policy
metadata:
name: "default-networkPolicy"
spec:
rules:
- name: "default-networkPolicy"
match:
resources:
kinds:
- Namespace
name: "devtest"
generate:
kind: NetworkPolicy
name: default-networkPolicy
data:
spec:
# select all pods in the namespace
podSelector: {}
policyTypes:
- Ingress
- Egress
ingress:
- from:
# allow traffic from any pod in a
# namespace with the label app=prod
- namespaceSelector:
matchLabels:
app: prod
# deny all the egrass traffic
egress:
- {}