Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Networkpolicy - Allow existing namespace #1007

Open
mtparet opened this issue Apr 15, 2022 · 3 comments
Open

Networkpolicy - Allow existing namespace #1007

mtparet opened this issue Apr 15, 2022 · 3 comments
Labels
enhancement New feature or request

Comments

@mtparet
Copy link

mtparet commented Apr 15, 2022

Describe the bug
When networkpolicies are activated, mizu does not work.

Also we cannot pre-setup networkpolicy inside mizu namespace because mizu refuse to start if the namespace mizu already exist.

To Reproduce
Steps to reproduce the behavior:

  1. Install any networkpolicies using calico
  2. Start mizu tap
  3. No traffic

Expected behavior
3 . See traffic

@gadotroee
Copy link
Contributor

gadotroee commented Apr 15, 2022

Hi @mtparet,

First I can suggest you working with mizu in "namespace restricted mode" [explanation about this mode can be found here - mizu-permissions] in this mode mizu will not create namespace, it will create the resources in an existing namespace (the limitation is that it will be able to capture only traffic from this namespace).

Also, You are welcome to propose changes yourself, if you want to suggest code edit that allow running mizu in "regular" mode and not create the namespace. You can check of wiki for project documentation, or you can reach out on slack for any question we will be glad to support you.

@gadotroee gadotroee added the enhancement New feature or request label Apr 18, 2022
@mtparet
Copy link
Author

mtparet commented Apr 19, 2022

Hi @gadotroee,

Thanks for the answer, I will try to propose the change to allow using existing mizu namespace with custom network policies or best perhaps creating network policies for mizu directly ?

@gadotroee
Copy link
Contributor

gadotroee commented Apr 19, 2022

Hi @gadotroee,

Thanks for the answer, I will try to propose the change to allow using existing mizu namespace with custom network policies or best perhaps creating network policies for mizu directly ?

I'm not sure that every mizu run need to create the network policies, but you are welcome to propose this change and if it works well it can be the change..

Anyway any help you need or more details - we are here

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants