Skip to content

Add optional default-deny NetworkPolicy template.#18

Merged
mbaldessari merged 1 commit intovalidatedpatterns:mainfrom
p-rog:add-default-deny-network-policy
Apr 30, 2026
Merged

Add optional default-deny NetworkPolicy template.#18
mbaldessari merged 1 commit intovalidatedpatterns:mainfrom
p-rog:add-default-deny-network-policy

Conversation

@p-rog
Copy link
Copy Markdown

@p-rog p-rog commented Apr 30, 2026

Add optional default-deny NetworkPolicy template

Add a namespace-wide default-deny NetworkPolicy that blocks all ingress
and egress for pods without an explicit allow policy. Gated by
defaultDenyNetworkPolicy.enabled (default false) so existing patterns
are unaffected.

Patterns that need zero-trust network isolation can enable this and
provide per-pod allow rules via vault.server.networkPolicy (already
supported by the upstream vault subchart).

Tested on an OpenShift 4.21 cluster with the layered-zero-trust pattern.

@mbaldessari mbaldessari merged commit fe9d781 into validatedpatterns:main Apr 30, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants