Skip to content

Chart: optional, provider-aware NetworkPolicy template (opt-in) #383

Description

@resker

Summary

Add an optional, opt-in NetworkPolicy template to the Topograph Helm chart so the chart can provision the network access its own components need when deployed onto clusters that enforce a default-deny posture.

Motivation

Some platforms employ a global default-deny security posture and expect each add-on chart installed afterward to bring the network policy its own workloads require, rather than the platform attempting to maintain a per-component carve-out centrally. Because the Topograph chart is generic (not platform-specific), a self-contained, opt-in policy keeps the chart portable while letting deny-all environments adopt it without editing central policy.

Proposal

Add networkPolicy.enabled (default false) that renders a standard networking.k8s.io/v1 NetworkPolicy (portable across CNIs that honor Kubernetes NetworkPolicy, e.g., Calico, Cilium). When enabled, it should cover both directions the components actually need:

Ingress

  • To the Topograph API Service port (49021 by default) from within the release namespace.
  • From the Prometheus scraper namespace when serviceMonitor.enabled: true.

Egress (provider-aware)

  • DNS (kube-dns) and the Kubernetes API server for all components.
  • For the netq provider: egress to the configured NetQ endpoint (host/port from provider params) — the current doc snippet is ingress-only and does not cover this.
  • infiniband-k8s / dra need no extra egress beyond DNS + API server.

Suggested shape (illustrative):

networkPolicy:
  enabled: false
  # Namespace running Prometheus (used when serviceMonitor.enabled: true)
  prometheusNamespace: monitoring
  # Extra egress rules for providers that reach external endpoints (e.g. netq)
  extraEgress: []

Notes / open questions

  • Policy-engine ordering: on clusters where the deny-all is expressed as a Calico GlobalNetworkPolicy (rather than a namespaced Kubernetes NetworkPolicy), the interaction/precedence between a chart-shipped NetworkPolicy and a cluster GlobalNetworkPolicy should be validated — a chart-shipped allow may not override a GNP deny depending on tier/order. Worth documenting the expectation.
  • Keep the template opt-in and default-off so it is inert on clusters that don't enforce NetworkPolicy.
  • Scope is intentionally network-layer only. Pod-security admission (e.g., the infiniband-k8s broker running privileged with a /sys/class hostPath) is admission control and cannot be self-granted by a workload chart — that exemption necessarily remains an operator/platform action and is out of scope here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions