Conversation
The agent's HTTP port served the full resource graph, a pod-cache debug endpoint and a log-level setter with no auth, and the production example put that port on the internet through an nginx Ingress on `/`. NOFireAI/edge#129 moves those endpoints to a loopback-only admin port, leaving only /healthz and /metrics on the Service port. Add a NetworkPolicy, enabled by default, that admits ingress to the agent pod only on config.serverPort (kubelet probes, Prometheus) and service.dnstapPort (CoreDNS dnstap). Egress is left open. Peers per port are configurable and default to any source. The pod selector excludes edge-proxy pods: they share the name/instance labels and carry a component label, and the policy would otherwise cut off their 8081 metrics. Delete templates/ingress.yaml and the ingress values. It only ever targeted the agent's HTTP port, whose only remaining content is health and metrics. Remove the Ingress block and the webhook.site publisher URLs from examples/production-values.yaml. Bump the chart to 0.6.0: the ingress.* values are removed. Refs NOFireAI/edge#129 Signed-off-by: Sergios Aftsidis <sergios@nofire.ai>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Chart half of NOFireAI/edge#129. The agent's HTTP port had a ClusterIP Service and no NetworkPolicy, and
examples/production-values.yamlenabled an nginx Ingress on/that would publish/graphto the internet.templates/networkpolicy.yaml, on by default (networkPolicy.enabled). It allows ingress to the agent pod only onconfig.serverPortandservice.dnstapPort, with sources set innetworkPolicy.httpFrom/dnstapFrom(default: any). Egress is not restricted. It excludes edge-proxy pods so their metrics port keeps working.templates/ingress.yamland theingress:values; the template only ever targeted the agent's HTTP port.examples/production-values.yaml: drop the Ingress block and both webhook.site URLs.Testing
helm lint(default and production values),helm templatewith the policy on, off and with source lists,kubeconform -strict(k8s 1.30): 14 valid, 0 invalid.Notes
/graphin-cluster on 8080; the protection is complete once both ship.ingress.enabled.Written with AI assistance (Claude Code).
Refs NOFireAI/edge#129, https://github.com/NOFireAI/edge/pull/149