-
Notifications
You must be signed in to change notification settings - Fork 12
Added matchExpression and additional policy to np generator #2860
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
simonklb
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What is the reason for the additional? Looks like it goes against the whole idea of generating netpols. 😄
Purely for backwards capability. Since the option existed, I assumed it was used somewhere. I agree it would be nice to avoid if possible. |
| {{- with $policy.podSelectorLabels }} | ||
| matchLabels: {{- toYaml . | nindent 6 }} | ||
| {{- else }} {} {{- end }} | ||
| {{- end }} | ||
| {{- with $policy.podSelectorExpressions }} | ||
| matchExpressions: {{- toYaml . | nindent 6 }} | ||
| {{- end }} | ||
| {{- if not (or $policy.podSelectorLabels $policy.podSelectorExpressions) }} {} {{- end }} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nit, could you sort expressions before labels?
| # kind: NetworkPolicy | ||
| # apiVersion: networking.k8s.io/v1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Another nit:
| # kind: NetworkPolicy | |
| # apiVersion: networking.k8s.io/v1 | |
| # apiVersion: networking.k8s.io/v1 | |
| # kind: NetworkPolicy |
| # - ports: | ||
| # - tcp: 53 | ||
| # - udp: 53 | ||
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| {{- if .Values.additional }} | ||
| {{- .Values.additional }} | ||
| {{- end }} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| {{- if .Values.additional }} | |
| {{- .Values.additional }} | |
| {{- end }} | |
| {{- with .Values.additional }} | |
| {{- . }} | |
| {{- end }} |
Simplification
I do think it is fine to include to not cause breakage, as we do use it as a means to add some netpols, though I would be happy to see us migrate to the "new" style for all including existing ips and ports options. 😄 |
Warning
This is a public repository, ensure not to disclose:
What kind of PR is this?
Required: Mark one of the following that is applicable:
Optional: Mark one or more of the following that are applicable:
Important
Breaking changes should be marked
kind/admin-changeorkind/dev-changedepending on typeCritical security fixes should be marked with
kind/securityWhat does this PR do / why do we need this PR?
Adds some necessary changes to be used by the other PRs refactoring all old netpols into the generator.
Information to reviewers
Checklist