Add Cilium Network Policies for aws-loadbalancer-controller-app
and aws-pod-identity-webhook
#3804
Labels
team/phoenix
Team Phoenix
In case of customers wanting to improve cluster security, the Cilium Cluster Wide Policy, blocking the IMDSv2 access can be added.
The policy itself can look like:
However there are still two types of workloads on GS side that require adjustments, such that the cluster wide policy can be applied without exceptions:
aws-pod-identity-webhook-app
:aws-loadbalancer-controller-app
:We should cater and add explicitly Cilium Network Policies such that the Cluster Wide Policy does not affect mentioned workloads.
Acceptance criteria:
aws-pod-identity-webhook-app
aws-loadbalancer-controller-app
Related issues:
The text was updated successfully, but these errors were encountered: