-
Notifications
You must be signed in to change notification settings - Fork 2.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docs: add documentation for policy-cidr-match-mode=nodes #28421
Conversation
This looks good, but What about kube-apiserver? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@squeed 👋🏻 This needs some minor changes, otherwise LGTM for docs.
ee9c200
to
110f742
Compare
Hmm, I'm not sure if that's needed. From an end-user perspective, kube-apsierver is a selectable entity, and that logic hasn't changed. The only difference w.r.t. policy calculations is that nodes are included in CIDR / ipBlock selectors. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@squeed Thanks for the updates, one more set of minor changes then LGTM
And kube-apiserver, right? We should call out that the kube-apiserver is now selectable by |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Some minor nits.
110f742
to
42e9595
Compare
42e9595
to
cedfbbd
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, just two more minor nits
@zacharysarah can you give this a re-review? Thanks! |
This feature, added in cilium#27464, allows for CIDR / ipBlock selectors to reference nodes within the cluster. Previously, nodes were only selectable via an entity selector. This adds some basic documentation to the feature. Signed-off-by: Casey Callendrello <cdc@isovalent.com>
cedfbbd
to
038efb5
Compare
/test |
This feature, added in #27464, allows for CIDR / ipBlock selectors to reference nodes within the cluster. Previously, nodes were only selectable via an entity selector.
This adds some basic documentation to the feature.