From 3c73156e64c4ac0515e5c21d3e98601d26de48f1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Patrick=20Sch=C3=B6nthaler?= Date: Tue, 17 Sep 2024 09:31:07 +0200 Subject: [PATCH] Add missing networkpolicy for seaweedfs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Patrick Schönthaler --- .github/workflows/pipeline_swfs_test.yaml | 2 +- contrib/seaweedfs/base/kustomization.yaml | 1 + .../base/seadweedfs-networkpolicy.yaml | 28 +++++++++++++++++++ contrib/seaweedfs/istio/kustomization.yaml | 1 + 4 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 contrib/seaweedfs/base/seadweedfs-networkpolicy.yaml diff --git a/.github/workflows/pipeline_swfs_test.yaml b/.github/workflows/pipeline_swfs_test.yaml index c2ae3ab99d..f3d52d1ad2 100644 --- a/.github/workflows/pipeline_swfs_test.yaml +++ b/.github/workflows/pipeline_swfs_test.yaml @@ -53,7 +53,7 @@ jobs: run: | kustomize build contrib/seaweedfs/istio | kubectl apply -f - kubectl -n kubeflow wait --for=condition=available --timeout=600s deploy/seaweedfs - kubectl -n kubeflow exec deploy/seaweedfs -c seaweedfs -- sh -c "echo \"s3.configure -user minio -access_key minio -secret_key minio123 -actions Read,Write -apply\" | /usr/bin/weed shell" + kubectl -n kubeflow exec deploy/seaweedfs -c seaweedfs -- sh -c "echo \"s3.configure -user minio -access_key minio -secret_key minio123 -actions Read,Write,List -apply\" | /usr/bin/weed shell" - name: port forward run: | diff --git a/contrib/seaweedfs/base/kustomization.yaml b/contrib/seaweedfs/base/kustomization.yaml index fc31272690..fca6773739 100644 --- a/contrib/seaweedfs/base/kustomization.yaml +++ b/contrib/seaweedfs/base/kustomization.yaml @@ -6,3 +6,4 @@ resources: - seaweedfs-deployment.yaml - seaweedfs-pvc.yaml - seaweedfs-service.yaml +- seadweedfs-networkpolicy.yaml \ No newline at end of file diff --git a/contrib/seaweedfs/base/seadweedfs-networkpolicy.yaml b/contrib/seaweedfs/base/seadweedfs-networkpolicy.yaml new file mode 100644 index 0000000000..6d2cffbdc9 --- /dev/null +++ b/contrib/seaweedfs/base/seadweedfs-networkpolicy.yaml @@ -0,0 +1,28 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: seaweedfs +spec: + ingress: + - from: + - namespaceSelector: + matchExpressions: + - key: app.kubernetes.io/part-of + operator: In + values: + - kubeflow-profile + - namespaceSelector: + matchExpressions: + - key: kubernetes.io/metadata.name + operator: In + values: + - istio-system + - podSelector: {} + podSelector: + matchExpressions: + - key: app + operator: In + values: + - seaweedfs + policyTypes: + - Ingress diff --git a/contrib/seaweedfs/istio/kustomization.yaml b/contrib/seaweedfs/istio/kustomization.yaml index 6b821ec6bb..a8b34ac8b6 100644 --- a/contrib/seaweedfs/istio/kustomization.yaml +++ b/contrib/seaweedfs/istio/kustomization.yaml @@ -1,5 +1,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization +namespace: kubeflow resources: - ../base/