From 3050c7c424430fa7aec59f20b5bd8b47d64fab61 Mon Sep 17 00:00:00 2001 From: jgrusewski Date: Mon, 2 Mar 2026 11:56:44 +0100 Subject: [PATCH] fix(netpol): allow DNS + egress for CI executor pods MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CI executor pods (label foxhunt-ci) were selected by allow-monitoring-scrape (which uses matchExpressions In [foxhunt, foxhunt-ci]) making them policy-controlled, but allow-dns only selected foxhunt pods via matchLabels. This blocked DNS resolution → git clone failure in deploy jobs. - Update allow-dns podSelector to matchExpressions In [foxhunt, foxhunt-ci] - Add ci-egress policy granting broad egress for ephemeral CI pods Co-Authored-By: Claude Opus 4.6 --- infra/k8s/network-policies/allow-dns.yaml | 8 +++++--- infra/k8s/network-policies/ci-egress.yaml | 18 ++++++++++++++++++ 2 files changed, 23 insertions(+), 3 deletions(-) create mode 100644 infra/k8s/network-policies/ci-egress.yaml diff --git a/infra/k8s/network-policies/allow-dns.yaml b/infra/k8s/network-policies/allow-dns.yaml index d9d3a0bd4..83f69d446 100644 --- a/infra/k8s/network-policies/allow-dns.yaml +++ b/infra/k8s/network-policies/allow-dns.yaml @@ -1,4 +1,4 @@ -# Allow all pods to reach CoreDNS (kube-system) for name resolution. +# Allow all foxhunt + CI pods to reach CoreDNS (kube-system) for name resolution. apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: @@ -8,8 +8,10 @@ metadata: app.kubernetes.io/part-of: foxhunt spec: podSelector: - matchLabels: - app.kubernetes.io/part-of: foxhunt + matchExpressions: + - key: app.kubernetes.io/part-of + operator: In + values: [foxhunt, foxhunt-ci] policyTypes: - Egress egress: diff --git a/infra/k8s/network-policies/ci-egress.yaml b/infra/k8s/network-policies/ci-egress.yaml new file mode 100644 index 000000000..2fc012915 --- /dev/null +++ b/infra/k8s/network-policies/ci-egress.yaml @@ -0,0 +1,18 @@ +# CI executor pods need broad egress: git clone (GitLab webservice), container +# registries, kubectl (K8s API), MinIO S3, and external tool downloads. +# These pods are ephemeral (minutes) — fine-grained egress adds little value. +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: ci-egress + namespace: foxhunt + labels: + app.kubernetes.io/part-of: foxhunt +spec: + podSelector: + matchLabels: + app.kubernetes.io/part-of: foxhunt-ci + policyTypes: + - Egress + egress: + - {}