Am i right in thinking that the bottlerocket OS does not need any ports open to be accessible from BottleRocket Update Operator? #3600
Replies: 2 comments 1 reply
-
Hello, It's worth noting that the The only other open ports are for exposing prometheus metrics from the I hope this helps, let me know if I can help clarify anything else! |
Beta Was this translation helpful? Give feedback.
-
@landbaychrisburrell FYI I created an issue about this for the upcoming brupop documentaiton bottlerocket-os/bottlerocket-project-website#406 |
Beta Was this translation helpful? Give feedback.
-
Hi
My understanding is that most of the interactions between the operator and the BottleRocket OS happen by updating the Shadow resources - as such, there is presumably zero ports required to be open - and so locking down the namespace with a policy that prevents all comms for pods into the operator's namespace would be fine?
Beta Was this translation helpful? Give feedback.
All reactions