NP does not enforce egress traffic to a matched service

Bug #1849139 reported by Maysa de Macedo Souza
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
kuryr-kubernetes
In Progress
Undecided
Maysa de Macedo Souza

Bug Description

We're not taking into account the case of a Network Policy with an egress rule to a pod that contains a Service sitting in front of it. Right now, only an egress rule to the matched pod is created, when one for the matched SVC is also required.

Changed in kuryr-kubernetes:
assignee: nobody → Maysa de Macedo Souza (maysa)
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Related fix merged to kuryr-kubernetes (master)

Reviewed: https://review.opendev.org/689102
Committed: https://git.openstack.org/cgit/openstack/kuryr-kubernetes/commit/?id=db1b24fcf627e00ca7a541164538bdfe860ddf2c
Submitter: Zuul
Branch: master

commit db1b24fcf627e00ca7a541164538bdfe860ddf2c
Author: Maysa Macedo <email address hidden>
Date: Thu Oct 17 08:54:47 2019 +0000

    Ensure Network Policy handles egress traffic to a SVC

    We're not taking into account the case of a Network Policy
    with an egress rule to a pod that contains a Service sitting
    in front of it. Right now, only an egress rule to the matched
    pod is created, when one for the matched SVC is also required.

    Related-Bug: 1849139
    Change-Id: I9830f30ba1fde3e5ec1a98fcbca22af992dd1bec

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Related fix proposed to kuryr-kubernetes (stable/train)

Related fix proposed to branch: stable/train
Review: https://review.opendev.org/694008

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Related fix merged to kuryr-kubernetes (stable/train)

Reviewed: https://review.opendev.org/694008
Committed: https://git.openstack.org/cgit/openstack/kuryr-kubernetes/commit/?id=0750ec9c5cba627692cff22b0c179951e94818b3
Submitter: Zuul
Branch: stable/train

commit 0750ec9c5cba627692cff22b0c179951e94818b3
Author: Maysa Macedo <email address hidden>
Date: Thu Oct 17 08:54:47 2019 +0000

    Ensure Network Policy handles egress traffic to a SVC

    We're not taking into account the case of a Network Policy
    with an egress rule to a pod that contains a Service sitting
    in front of it. Right now, only an egress rule to the matched
    pod is created, when one for the matched SVC is also required.

    Related-Bug: 1849139
    Change-Id: I9830f30ba1fde3e5ec1a98fcbca22af992dd1bec
    (cherry picked from commit db1b24fcf627e00ca7a541164538bdfe860ddf2c)

tags: added: in-stable-train
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.