Allow only in-cluster ingress for calico network policy

Viewed 278

I want to create a globalnetworkpolicy for an interface. I am using Calico HostendPoint for the interface and defining globalnetworkpolicy for the hostendpoint. I would like to create a globalnetworkpolicy that allows only ingress from within the cluster. A sample is given here.

In-cluster traffic is the traffic from pods and from nodes. I have the podCIDR, so I can use that to ensure that traffic from pods are allowed. How do I allow traffic from nodes' own IPAddresses as per the link above? What is the nodes' own IPaddresses mentioned in the link?

1 Answers

It is basically referring to Kubernetes node - more precisely to node resource, which is created when a calico/node instance is started. Calico automatically detects each node’s IP address and subnet, and alongside with AS association and tunnel address (IP-in-IP or VXLAN), they are listed in node resource configuration.

Related