Istio + NetworkPolicy

Viewed 659

How to explicitly allow inter-pod communication on a bare-metal cluster running Istio 1.8.4? What I try is:

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
  namespace: default
spec:
  policyTypes: [Ingress, Egress]
  podSelector: {}
  ingress: [] 
  egress: []
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: myapp
spec:
  policyTypes: [Ingress, Egress]
  podSelector:
    matchLabels:
      app: myapp

  ingress:
    - ports:
        - port: 8000
        - port: 6666 
      from:
        - podSelector:
            matchLabels:
              istio: ingress

  egress:
    - to:
      ports:
        - port: 8000
          protocol: TCP
        - port: 53
          protocol: TCP
        - port: 15012
          protocol: TCP
        - port: 15020
          protocol: TCP

Sidecar is unable to connect to the control plane.


Another question: how to restrict inter-pod communication if in most cases pods communicate via istio-ingressgateway?

0 Answers
Related