diff --git a/templates/netpol_ingress-miniooperator2miniopods.yaml b/templates/netpol_ingress-miniooperator2miniopods.yaml index 2b6cfd0..56f45ec 100644 --- a/templates/netpol_ingress-miniooperator2miniopods.yaml +++ b/templates/netpol_ingress-miniooperator2miniopods.yaml @@ -9,10 +9,8 @@ spec: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: minio-operator - kubernetes.io/metadata.name: ingress podSelector: matchLabels: v1.min.io/tenant: {{ .Values.tenant.tenant.name }} - app.kubernetes.io/name: ingress-nginx policyTypes: - Ingress diff --git a/templates/netpol_ingress-nginx2miniopods.yaml b/templates/netpol_ingress-nginx2miniopods.yaml new file mode 100644 index 0000000..1876de6 --- /dev/null +++ b/templates/netpol_ingress-nginx2miniopods.yaml @@ -0,0 +1,16 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: ingress-nginx2miniopods +# allow traffic from minio-operator NS to current NS across all ports +spec: + ingress: + - from: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress + podSelector: + matchLabels: + app.kubernetes.io/name: ingress-nginx + policyTypes: + - Ingress