Network Policy Spec for Nodes/VMs
Policy Specification
apiVersion: security.kubearmor.com/v1
kind:KubeArmorNetworkPolicy
metadata:
name: [policy name]
spec:
severity: [1-10] # --> optional
tags: ["tag", ...] # --> optional
message: [message] # --> optional
nodeSelector:
matchLabels:
[key1]: [value1]
[keyN]: [valueN]
ingress:
- from:
- ipBlock:
cidr: [IP address range]
iface: [if1, ...]
ports:
- protocol: [TCP|tcp|UDP|udp|SCTP|sctp]
port: [http|https|ssh|dns OR "port number"]
endPort: [port number]
egress:
- to:
- ipBlock:
cidr: [IP address range]
iface: [if1, ...]
ports:
- protocol: [TCP|tcp|UDP|udp|SCTP|sctp]
port: [http|https|ssh|dns OR "port number"]
endPort: [port number]
action: [Audit|Allow|Block]Policy Spec Description
Last updated
Was this helpful?