Files
semantica/deploy/kubernetes/networkpolicy.yaml
T
KaifAhmad1 b9e069301f fix(deploy): address security and correctness blockers from PR review
- gcp/cloudrun-service.yaml: add comment + README sed one-liner so PROJECT_ID
  is substituted before gcloud run services replace (was a literal placeholder
  that caused image-pull failure on the declarative deploy path)
- azure/main.parameters.json: replace wildcard allowedOrigins "*" with a
  REPLACE_ME placeholder; add README note to set the real URL after first deploy
- kubernetes/networkpolicy.yaml + helm networkpolicy template: add from: selector
  (ingress-nginx namespace + same-namespace pods) so ingress is no longer
  allow-all; restrict egress to FalkorDB port 6379 and DNS port 53 instead of
  the allow-all egress: - {} wildcard
- helm/values.yaml: expose networkPolicy.ingressNamespace and falkordbPort values
- kubernetes/deployment.yaml: add secretRef for knowledge-explorer-secrets so
  FALKORDB_PASSWORD is actually injected into the container
- app.py: add _mutation_bridge_installed guard to prevent closure stacking when
  the same GraphSession is passed to create_app() more than once; remove
  duplicate app.state.allowed_origins assignment (single source of truth is
  app.state.explorer_settings); add comment on falkordb_host/port dead config
- tests: update allowed_origins assertions to use explorer_settings dict
- .checkov.yaml: remove global CKV_K8S_21/28/30 suppressions; rely on per-file
  inline checkov:skip comments in cloudrun-service.yaml so future real K8s
  manifests are not silently exempted
2026-06-24 22:55:18 +05:30

43 lines
1.0 KiB
YAML

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: knowledge-explorer
namespace: semantica
labels:
app.kubernetes.io/name: knowledge-explorer
app.kubernetes.io/part-of: semantica
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: knowledge-explorer
policyTypes:
- Ingress
- Egress
ingress:
# Allow traffic from the ingress controller namespace.
# Adjust the namespace label if your ingress controller uses a different namespace.
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: ingress-nginx
ports:
- protocol: TCP
port: 8000
# Allow traffic from pods within the same namespace (e.g. monitoring sidecars).
- from:
- podSelector: {}
ports:
- protocol: TCP
port: 8000
egress:
# FalkorDB
- ports:
- protocol: TCP
port: 6379
# DNS resolution
- ports:
- protocol: UDP
port: 53
- protocol: TCP
port: 53